-
Notifications
You must be signed in to change notification settings - Fork 3.4k
CVE-2026-32597 - Upgrade pyJWT #32969
Copy link
Copy link
Open
Labels
Azure CLI TeamThe command of the issue is owned by Azure CLI teamThe command of the issue is owned by Azure CLI teamSecurity-Issuecustomer-reportedIssues that are reported by GitHub users external to the Azure organization.Issues that are reported by GitHub users external to the Azure organization.feature-request
Milestone
Description
Describe the bug
The current version of az-cli is using a vulnerable package PyJWT@2.10.1.
Related CVE - CVE-2026-32597
GHSA - GHSA-752w-5fwx-jx9f
Please upgrade it to at least 2.12.0
Related command
NA
Errors
NA
Issue script & Debug output
NA
Expected behavior
NA
Environment Summary
azure-cli 2.84.0 is affected along with previous versions.
Additional context
No response
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
Azure CLI TeamThe command of the issue is owned by Azure CLI teamThe command of the issue is owned by Azure CLI teamSecurity-Issuecustomer-reportedIssues that are reported by GitHub users external to the Azure organization.Issues that are reported by GitHub users external to the Azure organization.feature-request