Safety vulnerability ID: 68046
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Cognitojwt version 1.5.0 transitions from the outdated python-jose library, which relied on the ecdsa package containing unresolved vulnerabilities, to the more frequently updated joserfc library.
Latest version: 1.5.0
Decode and verify Amazon Cognito JWT tokens
- Switch from the outdated python-jose library that depends on ecdsa package that - in turn - contains unfixed vulnerabilities, to more commonly updated joserfc` library.
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application