-
Notifications
You must be signed in to change notification settings - Fork 3.4k
CVE-2026-32597 - Upgrade pyJWT #32969
Copy link
Copy link
Open
Labels
Azure CLI TeamThe command of the issue is owned by Azure CLI teamThe command of the issue is owned by Azure CLI teamSecurity-Issuecustomer-reportedIssues that are reported by GitHub users external to the Azure organization.Issues that are reported by GitHub users external to the Azure organization.feature-request
Milestone
Metadata
Metadata
Assignees
Labels
Azure CLI TeamThe command of the issue is owned by Azure CLI teamThe command of the issue is owned by Azure CLI teamSecurity-Issuecustomer-reportedIssues that are reported by GitHub users external to the Azure organization.Issues that are reported by GitHub users external to the Azure organization.feature-request
Describe the bug
The current version of az-cli is using a vulnerable package
PyJWT@2.10.1.Related CVE - CVE-2026-32597
GHSA - GHSA-752w-5fwx-jx9f
Please upgrade it to at least
2.12.0Related command
NA
Errors
NA
Issue script & Debug output
NA
Expected behavior
NA
Environment Summary
azure-cli 2.84.0 is affected along with previous versions.
Additional context
No response