
🚨 Critical vulnerability io.github.SureshKhemka/constraints-registry Unpatched critical vulnerability (CVE-2026-102268). A fixed version is available. Trust score: 50 → 0
Signal is active with 2 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected because is_pem_format does not recognize every PEM representation accepted by the cryptography loader. This occurs when an application mixes HMAC and asymmetric algorithms and supplies a mutated public-key PEM as raw key bytes. As a result, HMACAlgorithm.prepare_key treats the unrecognized asymmetric public key as an HMAC secret. Consequently, an attacker who knows the public key can forge authenticated HMAC tokens. This issue is fixed in version 2.14.0.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE

🚨 Critical vulnerability io.github.SureshKhemka/constraints-registry Unpatched critical vulnerability (CVE-2026-102268). A fixed version is available. Trust score: 50 → 0

🚨 Critical vulnerability io.github.redis/mcp-redis Unpatched critical vulnerability (CVE-2026-102268). A fixed version is available. Trust score: 69 → 0

NewNormal Security turns CVEs since the previous batch into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 29 Sep 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 📦 JWT signature verification bypass — a published public key is accepted as an HMAC secret, so anyone holding it forges a valid token (PyJWT CVE-2026-102268, CVE-2026-102266) 📦 HTTP client proxy and redirect policy bypass — the app's outbound requests leave past its egress allow-list (axios CVE-2026-101898, CVE-2026-101907) 📦 Notes-app database injection — a shared document runs unvalidated SQL against the importer's notebook database (SiYuan CVE-2026-101091, CVE-2026-101092) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #JWT #CSO #REDTEAM