It was discovered that PyJWT, a Python implementation of JSON web tokens insufficiently validated the "crit" header parameter, which could result in incomplete enforcement of authentication settings.
https://security-tracker.debian.org/tracker/DSA-6259-1
Continue reading...
https://security-tracker.debian.org/tracker/DSA-6259-1
Continue reading...

