Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

opentok-3.15.0-py2.py3-none-any.whl: 2 vulnerabilities (highest severity is: 6.5)

Open Beginner friendly
#272 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
64/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
python
Domain
backend, security

Research direction

Start with the Archiving/requirements.txt dependency path and inspect how opentok-3.15.0 brings in the transitive pyjwt 2.14.0 package. Check whether upgrading PyJWT to 2.15.0 resolves both listed CVEs, then verify that the dependency scan no longer reports them.

Written by the indexing model from the issue text.

Description

Mend: dependency security vulnerability
Vulnerable Library - opentok-3.15.0-py2.py3-none-any.whl

Sample Path to Dependency File: /sample/Archiving/requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260915102239_CCWDFH/python_PUWVTO/20260915102240/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260915102239_CCWDFH/python_PUWVTO/20260915102240/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260915102239_CCWDFH/python_PUWVTO/20260915102240/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260918151839_VHYKNR/python_FMYLDX/20260918151840/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260918151839_VHYKNR/python_FMYLDX/20260918151840/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260918151839_VHYKNR/python_FMYLDX/20260918151840/pyjwt-2.14.0-py3-none-any.whl

Vulnerabilities

Vulnerability Severity CVSS Exploit Maturity EPSS Dependency Type Fixed in (opentok version) Remediation Possible** Reachability
CVE-2026-102275 Medium 6.5 Not Defined 0.137% pyjwt-2.14.0-py3-none-any.whl Transitive N/A* ❌
CVE-2026-101918 Medium 5.3 Not Defined 0.291% pyjwt-2.14.0-py3-none-any.whl Transitive N/A* ❌

*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

CVE-2026-102275
Vulnerable Library - pyjwt-2.14.0-py3-none-any.whl

JSON Web Token implementation in Python

Library home page: https://files.pythonhosted.org/packages/9c/97/672cb32ce0dfea44b740cb7b4f97038463b9cf7c0ead1aacf595572851d6/pyjwt-2.14.0-py3-none-any.whl

Sample Path to Dependency File: /sample/HelloWorld/requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260915102239_CCWDFH/python_PUWVTO/20260915102240/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260915102239_CCWDFH/python_PUWVTO/20260915102240/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260915102239_CCWDFH/python_PUWVTO/20260915102240/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260918151839_VHYKNR/python_FMYLDX/20260918151840/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260918151839_VHYKNR/python_FMYLDX/20260918151840/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260918151839_VHYKNR/python_FMYLDX/20260918151840/pyjwt-2.14.0-py3-none-any.whl

Dependency Hierarchy:

  • opentok-3.15.0-py2.py3-none-any.whl (Root Library)
    • ❌ pyjwt-2.14.0-py3-none-any.whl (Vulnerable Library)

Found in base branch: main

Vulnerability Details

PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in jwt/algorithms.py is affected because private-JWK import path does not compare the public key derived from d with x. This occurs when an OKP private JWK supplies non-corresponding x and d components. As a result, identity derived from x can differ from operations performed with d. Consequently, if an integration also accepts private key parameters from a proof header without rejecting them, an attacker may use a stolen sender-constrained token without the legitimate private key. This issue is fixed in version 2.15.0.

Publish Date: 2026-09-28

URL: CVE-2026-102275

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 0.137%

CVSS 3 Score Details (6.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: High
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: Low
    • Integrity Impact: High
    • Availability Impact: None

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-09-28

Fix Resolution: pyjwt - 2.15.0

CVE-2026-101918
Vulnerable Library - pyjwt-2.14.0-py3-none-any.whl

JSON Web Token implementation in Python

Library home page: https://files.pythonhosted.org/packages/9c/97/672cb32ce0dfea44b740cb7b4f97038463b9cf7c0ead1aacf595572851d6/pyjwt-2.14.0-py3-none-any.whl

Sample Path to Dependency File: /sample/HelloWorld/requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260915102239_CCWDFH/python_PUWVTO/20260915102240/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260915102239_CCWDFH/python_PUWVTO/20260915102240/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260915102239_CCWDFH/python_PUWVTO/20260915102240/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260918151839_VHYKNR/python_FMYLDX/20260918151840/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260918151839_VHYKNR/python_FMYLDX/20260918151840/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260918151839_VHYKNR/python_FMYLDX/20260918151840/pyjwt-2.14.0-py3-none-any.whl

Dependency Hierarchy:

  • opentok-3.15.0-py2.py3-none-any.whl (Root Library)
    • ❌ pyjwt-2.14.0-py3-none-any.whl (Vulnerable Library)

Found in base branch: main

Vulnerability Details

PyJWT is a Python implementation of JSON Web Token standards. From 2.0.0a1 until 2.15.0, PyJWT PyJWKClient.get_signing_key_from_jwt is affected because payload parser catches ValueError but not RecursionError. This occurs when an attacker-controlled recursively nested payload reaches json.loads. As a result, documented PyJWT exception handling does not contain the failure. Consequently, an unauthenticated request can raise an exception that may produce an HTTP 500 response. The advisory-defined affected implementation also includes jwt/api_jwt.py, verify_signature=False. This issue is fixed in version 2.15.0.

Publish Date: 2026-09-28

URL: CVE-2026-101918

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 0.291%

CVSS 3 Score Details (5.3)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: None
    • Availability Impact: Low

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Release Date: 2026-09-28

Fix Resolution: pyjwt - 2.15.0

Dominant language
Python
Stars
72
Forks
80
Avg merge
1m
Merged PRs (30d)
1

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from opentok/Opentok-Python-SDK

All issues in opentok/Opentok-Python-SDK

Similar issues

More Python issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.