Debian Package Tracker
Register | Log in
Subscribe

joserfc

Python library for JSON Object Signing and Encryption (JOSE)

Choose email to subscribe with

general
  • source: joserfc (main)
  • version: 1.4.3-1
  • maintainer: Debian Python Team (DMD)
  • uploaders: Edward Betts [DMD]
  • arch: all
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • stable: 1.1.0-1
  • testing: 1.4.3-1
  • unstable: 1.4.3-1
versioned links
  • 1.1.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.4.3-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python3-joserfc
action needed
A new upstream version is available: 1.5.0 high
A new upstream version 1.5.0 is available, you should consider packaging it.
Created: 2025-11-30 Last update: 2025-12-03 11:30
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2025-65015: joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions from 1.3.3 to before 1.3.5 and from 1.4.0 to before 1.4.2, the ExceededSizeError exception messages are embedded with non-decoded JWT token parts and may cause Python logging to record an arbitrarily large, forged JWT payload. In situations where a misconfigured — or entirely absent — production-grade web server sits in front of a Python web application, an attacker may be able to send arbitrarily large bearer tokens in the HTTP request headers. When this occurs, Python logging or diagnostic tools (e.g., Sentry) may end up processing extremely large log messages containing the full JWT header during the joserfc.jwt.decode() operation. The same behavior also appears when validating claims and signature payload sizes, as the library raises joserfc.errors.ExceededSizeError() with the full payload embedded in the exception message. Since the payload is already fully loaded into memory at this stage, the library cannot prevent or reject it. This issue has been patched in versions 1.3.5 and 1.4.2.
Created: 2025-11-19 Last update: 2025-11-22 06:30
news
[rss feed]
  • [2025-11-22] joserfc 1.4.3-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-19] Accepted joserfc 1.4.3-1 (source) into unstable (Edward Betts)
  • [2025-11-09] joserfc 1.4.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-07] Accepted joserfc 1.4.1-1 (source) into unstable (Edward Betts)
  • [2025-10-12] joserfc 1.4.0-1 MIGRATED to testing (Debian testing watch)
  • [2025-10-10] Accepted joserfc 1.4.0-1 (source) into unstable (Edward Betts)
  • [2025-09-26] joserfc 1.3.4-1 MIGRATED to testing (Debian testing watch)
  • [2025-09-24] Accepted joserfc 1.3.4-1 (source) into unstable (Edward Betts)
  • [2025-09-10] joserfc 1.3.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-09-06] Accepted joserfc 1.3.2-1 (source) into unstable (Edward Betts)
  • [2025-09-01] joserfc 1.3.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-28] Accepted joserfc 1.3.1-1 (source) into unstable (Edward Betts)
  • [2025-08-13] joserfc 1.2.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-07-31] Accepted joserfc 1.2.2-1 (source) into unstable (Edward Betts)
  • [2025-07-09] Accepted joserfc 1.2.0-1 (source) into unstable (Edward Betts)
  • [2025-06-19] joserfc 1.1.0-1 MIGRATED to testing (Debian testing watch)
  • [2025-05-30] Accepted joserfc 1.1.0-1 (source) into unstable (Edward Betts)
  • [2025-03-09] joserfc 1.0.4-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-06] Accepted joserfc 1.0.4-1 (source) into unstable (Edward Betts)
  • [2025-02-15] joserfc 1.0.3-1 MIGRATED to testing (Debian testing watch)
  • [2025-02-12] Accepted joserfc 1.0.3-1 (source) into unstable (Edward Betts)
  • [2025-01-28] joserfc 1.0.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-01-24] Accepted joserfc 1.0.2-1 (source) into unstable (Edward Betts)
  • [2024-12-10] joserfc 1.0.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-12-07] Accepted joserfc 1.0.1-1 (source) into unstable (Edward Betts)
  • [2024-08-02] joserfc 1.0.0-2 MIGRATED to testing (Debian testing watch)
  • [2024-07-31] Accepted joserfc 1.0.0-2 (source) into unstable (Edward Betts)
  • [2024-07-28] Accepted joserfc 1.0.0-1 (source all) into unstable (Debian FTP Masters) (signed by: Edward Betts)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • l10n (-, 46)
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1.4.3-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing