opentok-3.15.0-py2.py3-none-any.whl: 2 vulnerabilities (highest severity is: 6.5)
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 64/100
Research direction
Start with the Archiving/requirements.txt dependency path and inspect how opentok-3.15.0 brings in the transitive pyjwt 2.14.0 package. Check whether upgrading PyJWT to 2.15.0 resolves both listed CVEs, then verify that the dependency scan no longer reports them.
Written by the indexing model from the issue text.
Description
Vulnerable Library - opentok-3.15.0-py2.py3-none-any.whl
Sample Path to Dependency File: /sample/Archiving/requirements.txt
Path to vulnerable library: /tmp/ws-ua_20260915102239_CCWDFH/python_PUWVTO/20260915102240/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260915102239_CCWDFH/python_PUWVTO/20260915102240/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260915102239_CCWDFH/python_PUWVTO/20260915102240/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260918151839_VHYKNR/python_FMYLDX/20260918151840/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260918151839_VHYKNR/python_FMYLDX/20260918151840/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260918151839_VHYKNR/python_FMYLDX/20260918151840/pyjwt-2.14.0-py3-none-any.whl
Vulnerabilities
| Vulnerability | Severity | CVSS |
Exploit Maturity | EPSS | Dependency | Type | Fixed in (opentok version) | Remediation Possible** | Reachability |
|---|---|---|---|---|---|---|---|---|---|
| CVE-2026-102275 | Medium |
6.5 | Not Defined | 0.137% | pyjwt-2.14.0-py3-none-any.whl | Transitive | N/A* | ❌ | |
| CVE-2026-101918 | Medium |
5.3 | Not Defined | 0.291% | pyjwt-2.14.0-py3-none-any.whl | Transitive | N/A* | ❌ |
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2026-102275
Vulnerable Library - pyjwt-2.14.0-py3-none-any.whl
JSON Web Token implementation in Python
Library home page: https://files.pythonhosted.org/packages/9c/97/672cb32ce0dfea44b740cb7b4f97038463b9cf7c0ead1aacf595572851d6/pyjwt-2.14.0-py3-none-any.whl
Sample Path to Dependency File: /sample/HelloWorld/requirements.txt
Path to vulnerable library: /tmp/ws-ua_20260915102239_CCWDFH/python_PUWVTO/20260915102240/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260915102239_CCWDFH/python_PUWVTO/20260915102240/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260915102239_CCWDFH/python_PUWVTO/20260915102240/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260918151839_VHYKNR/python_FMYLDX/20260918151840/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260918151839_VHYKNR/python_FMYLDX/20260918151840/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260918151839_VHYKNR/python_FMYLDX/20260918151840/pyjwt-2.14.0-py3-none-any.whl
Dependency Hierarchy:
- opentok-3.15.0-py2.py3-none-any.whl (Root Library)
- ❌ pyjwt-2.14.0-py3-none-any.whl (Vulnerable Library)
Found in base branch: main
Vulnerability Details
PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in jwt/algorithms.py is affected because private-JWK import path does not compare the public key derived from d with x. This occurs when an OKP private JWK supplies non-corresponding x and d components. As a result, identity derived from x can differ from operations performed with d. Consequently, if an integration also accepts private key parameters from a proof header without rejecting them, an attacker may use a stolen sender-constrained token without the legitimate private key. This issue is fixed in version 2.15.0.
Publish Date: 2026-09-28
URL: CVE-2026-102275
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 0.137%
CVSS 3 Score Details (6.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: High
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Release Date: 2026-09-28
Fix Resolution: pyjwt - 2.15.0
CVE-2026-101918
Vulnerable Library - pyjwt-2.14.0-py3-none-any.whl
JSON Web Token implementation in Python
Library home page: https://files.pythonhosted.org/packages/9c/97/672cb32ce0dfea44b740cb7b4f97038463b9cf7c0ead1aacf595572851d6/pyjwt-2.14.0-py3-none-any.whl
Sample Path to Dependency File: /sample/HelloWorld/requirements.txt
Path to vulnerable library: /tmp/ws-ua_20260915102239_CCWDFH/python_PUWVTO/20260915102240/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260915102239_CCWDFH/python_PUWVTO/20260915102240/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260915102239_CCWDFH/python_PUWVTO/20260915102240/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260918151839_VHYKNR/python_FMYLDX/20260918151840/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260918151839_VHYKNR/python_FMYLDX/20260918151840/pyjwt-2.14.0-py3-none-any.whl,/tmp/ws-ua_20260918151839_VHYKNR/python_FMYLDX/20260918151840/pyjwt-2.14.0-py3-none-any.whl
Dependency Hierarchy:
- opentok-3.15.0-py2.py3-none-any.whl (Root Library)
- ❌ pyjwt-2.14.0-py3-none-any.whl (Vulnerable Library)
Found in base branch: main
Vulnerability Details
PyJWT is a Python implementation of JSON Web Token standards. From 2.0.0a1 until 2.15.0, PyJWT PyJWKClient.get_signing_key_from_jwt is affected because payload parser catches ValueError but not RecursionError. This occurs when an attacker-controlled recursively nested payload reaches json.loads. As a result, documented PyJWT exception handling does not contain the failure. Consequently, an unauthenticated request can raise an exception that may produce an HTTP 500 response. The advisory-defined affected implementation also includes jwt/api_jwt.py, verify_signature=False. This issue is fixed in version 2.15.0.
Publish Date: 2026-09-28
URL: CVE-2026-101918
Threat Assessment
Exploit Maturity: Not Defined
EPSS: 0.291%
CVSS 3 Score Details (5.3)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
Suggested Fix
Type: Upgrade version
Release Date: 2026-09-28
Fix Resolution: pyjwt - 2.15.0
- Dominant language
- Python
- Stars
- 72
- Forks
- 80
- Avg merge
- 1m
- Merged PRs (30d)
- 1
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from opentok/Opentok-Python-SDK
-
Renovate Dashboard 🚧Open
Difficulty 4/5 3-5 days Newbie friendliness 20/100
opentok/Opentok-Python-SDK#266 ·
-
Mend: dependency security vulnerability
Difficulty 4/5 3-5 days Newbie friendliness 35/100
opentok/Opentok-Python-SDK#252 · 2 comments ·
All issues in opentok/Opentok-Python-SDK
Similar issues
-
repo-audit
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
scverse/repo-health#20 ·
Maintainers usually reply within 1 day
-
/context/prime scope override double-prefixes an entity-ref project and drops its scoped memoriesOpen
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
phasespace-labs/palinode#232 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
collective/icalendar#1858 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
langflow-ai/langflow#15496 ·
Maintainers usually reply within 1 day
CVSS