Skip to content

Is any action required for CVE-2022-29217 (PyJWT security vulnerability) #8499

Discussion options

You must be logged in to vote

I'll attempt to answer my question 😄

Looks like djangorestframework-jwt does indeed apply the JWT_ALGORITHM setting inside its jwt_encode_handler and jwt_decode_handler functions.

Based on my understanding, if the setting is present, it should be ok.

But any confirmation is welcome :)

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@tomchristie
Comment options

Answer selected by tomchristie
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants