Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package python-jwcrypto for openSUSE:Factory 
checked in at 2026-10-02 23:01:51
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/python-jwcrypto (Old)
 and      /work/SRC/openSUSE:Factory/.python-jwcrypto.new.1631729 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "python-jwcrypto"

Fri Oct  2 23:01:51 2026 rev:22 rq:1381872 version:1.6.1

Changes:
--------
--- /work/SRC/openSUSE:Factory/python-jwcrypto/python-jwcrypto.changes  
2026-09-07 11:30:37.209710846 +0200
+++ 
/work/SRC/openSUSE:Factory/.python-jwcrypto.new.1631729/python-jwcrypto.changes 
    2026-10-02 23:02:19.537736001 +0200
@@ -1,0 +2,10 @@
+Wed Sep 30 13:18:21 UTC 2026 - Nico Krapp <[email protected]>
+
+- Update to 1.6.1 (fixes CVE-2026-92091 (bsc#1280816))
+  * Avoid quadratic duplicate check on JWK key_ops by @lissy93
+    in #398
+  * Loop optimizations by @rjeffman in #397
+  * Simplify key_ops checks by @simo5 in #399
+  * Version 1.6.1 by @simo5 in #400
+
+-------------------------------------------------------------------

Old:
----
  jwcrypto-1.6.0.tar.gz

New:
----
  jwcrypto-1.6.1.tar.gz

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ python-jwcrypto.spec ++++++
--- /var/tmp/diff_new_pack.dBTNzO/_old  2026-10-02 23:02:20.808789200 +0200
+++ /var/tmp/diff_new_pack.dBTNzO/_new  2026-10-02 23:02:20.813789410 +0200
@@ -18,7 +18,7 @@
 
 %{?sle15_python_module_pythons}
 Name:           python-jwcrypto
-Version:        1.6.0
+Version:        1.6.1
 Release:        0
 Summary:        Python module package implementing JOSE Web standards
 License:        LGPL-3.0-only
@@ -47,7 +47,7 @@
 RFC 7520 - Examples of Protecting Content Using JSON Object Signing and 
Encryption (JOSE)
 
 %prep
-%setup -q -n jwcrypto-%{version}
+%autosetup -p1 -n jwcrypto-%{version}
 
 %build
 %pyproject_wheel

++++++ jwcrypto-1.6.0.tar.gz -> jwcrypto-1.6.1.tar.gz ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/jwcrypto-1.6.0/PKG-INFO new/jwcrypto-1.6.1/PKG-INFO
--- old/jwcrypto-1.6.0/PKG-INFO 2026-09-01 15:09:36.408043000 +0200
+++ new/jwcrypto-1.6.1/PKG-INFO 2026-09-15 23:22:24.280162300 +0200
@@ -1,6 +1,6 @@
 Metadata-Version: 2.4
 Name: jwcrypto
-Version: 1.6.0
+Version: 1.6.1
 Summary: Implementation of JOSE Web standards
 Home-page: https://github.com/latchset/jwcrypto
 Maintainer: JWCrypto Project Contributors
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/jwcrypto-1.6.0/jwcrypto/jwk.py 
new/jwcrypto-1.6.1/jwcrypto/jwk.py
--- old/jwcrypto-1.6.0/jwcrypto/jwk.py  2026-09-01 15:09:21.000000000 +0200
+++ new/jwcrypto-1.6.1/jwcrypto/jwk.py  2026-09-15 23:22:04.000000000 +0200
@@ -247,6 +247,16 @@
                          'deriveBits': 'Derive bits not to be used as a key'}
 """Registry of allowed operations"""
 
+# Key Operations registry but augmented with use pair matching.
+JWKOpAndUsePairs = {'sign': 'sig',
+                    'verify': 'sig',
+                    'encrypt': 'enc',
+                    'decrypt': 'enc',
+                    'wrapKey': 'enc',
+                    'unwrapKey': 'enc',
+                    'deriveKey': 'enc',
+                    'deriveBits': 'enc'}
+
 JWKpycaCurveMap = {'secp256r1': 'P-256',
                    'secp384r1': 'P-384',
                    'secp521r1': 'P-521',
@@ -707,28 +717,16 @@
 
         # check key_ops
         if 'key_ops' in newkey:
-            for ko in newkey['key_ops']:
-                cnt = 0
-                for cko in newkey['key_ops']:
-                    if ko == cko:
-                        cnt += 1
-                if cnt != 1:
-                    raise InvalidJWKValue('Duplicate values in "key_ops"')
-
-        # check use/key_ops consistency
-        if 'use' in newkey and 'key_ops' in newkey:
-            sigl = ['sign', 'verify']
-            encl = ['encrypt', 'decrypt', 'wrapKey', 'unwrapKey',
-                    'deriveKey', 'deriveBits']
-            if newkey['use'] == 'sig':
-                for op in encl:
-                    if op in newkey['key_ops']:
-                        raise InvalidJWKValue('Incompatible "use" and'
-                                              ' "key_ops" values specified at'
-                                              ' the same time')
-            elif newkey['use'] == 'enc':
-                for op in sigl:
-                    if op in newkey['key_ops']:
+            if len(newkey['key_ops']) > len(JWKOperationsRegistry):
+                raise InvalidJWKValue('Unknown or duplicate "key_ops" values')
+
+            if len(set(newkey['key_ops'])) != len(newkey['key_ops']):
+                raise InvalidJWKValue('Duplicate values in "key_ops"')
+
+            # check use/key_ops consistency
+            if 'use' in newkey:
+                for op in newkey['key_ops']:
+                    if newkey['use'] != JWKOpAndUsePairs.get(op, 'bad'):
                         raise InvalidJWKValue('Incompatible "use" and'
                                               ' "key_ops" values specified at'
                                               ' the same time')
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/jwcrypto-1.6.0/jwcrypto/jwt.py 
new/jwcrypto-1.6.1/jwcrypto/jwt.py
--- old/jwcrypto-1.6.0/jwcrypto/jwt.py  2026-09-01 15:09:21.000000000 +0200
+++ new/jwcrypto-1.6.1/jwcrypto/jwt.py  2026-09-15 23:22:04.000000000 +0200
@@ -535,12 +535,8 @@
                         cclaims = value
                     else:
                         cclaims = [value]
-                    found = False
-                    for v in cclaims:
-                        if v in tclaims:
-                            found = True
-                            break
-                    if not found:
+                    token_audiences = set(tclaims)
+                    if not any(v in token_audiences for v in cclaims):
                         raise JWTInvalidClaimValue(
                             "Invalid '{}' value. Expected '{}' in '{}'".format(
                                 name, claims[name], value))
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/jwcrypto-1.6.0/jwcrypto/tests.py 
new/jwcrypto-1.6.1/jwcrypto/tests.py
--- old/jwcrypto-1.6.0/jwcrypto/tests.py        2026-09-01 15:09:21.000000000 
+0200
+++ new/jwcrypto-1.6.1/jwcrypto/tests.py        2026-09-15 23:22:04.000000000 
+0200
@@ -685,6 +685,11 @@
         with self.assertRaises(jwk.InvalidJWKValue):
             jwk.JWK(kty='oct', k=b'\x01')
 
+    def test_key_ops_duplicates(self):
+        jwk.JWK(kty='oct', k='AAAA', key_ops=['sign', 'verify'])
+        with self.assertRaises(jwk.InvalidJWKValue):
+            jwk.JWK(kty='oct', k='AAAA', key_ops=['sign', 'verify', 'sign'])
+
     def test_create_pubKeys_eddsa(self):
         keylist = PublicKeys_EdDsa['keys']
         for key in keylist:
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/jwcrypto-1.6.0/jwcrypto/version.py 
new/jwcrypto-1.6.1/jwcrypto/version.py
--- old/jwcrypto-1.6.0/jwcrypto/version.py      2026-09-01 15:09:21.000000000 
+0200
+++ new/jwcrypto-1.6.1/jwcrypto/version.py      2026-09-15 23:22:04.000000000 
+0200
@@ -1 +1 @@
-__version__ = "1.6.0"
+__version__ = "1.6.1"
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/jwcrypto-1.6.0/jwcrypto.egg-info/PKG-INFO 
new/jwcrypto-1.6.1/jwcrypto.egg-info/PKG-INFO
--- old/jwcrypto-1.6.0/jwcrypto.egg-info/PKG-INFO       2026-09-01 
15:09:36.000000000 +0200
+++ new/jwcrypto-1.6.1/jwcrypto.egg-info/PKG-INFO       2026-09-15 
23:22:24.000000000 +0200
@@ -1,6 +1,6 @@
 Metadata-Version: 2.4
 Name: jwcrypto
-Version: 1.6.0
+Version: 1.6.1
 Summary: Implementation of JOSE Web standards
 Home-page: https://github.com/latchset/jwcrypto
 Maintainer: JWCrypto Project Contributors

Reply via email to