Script 'mail_helper' called by obssrc
Hello community,
here is the log from the commit of package python-jwcrypto for openSUSE:Factory
checked in at 2026-10-02 23:01:51
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/python-jwcrypto (Old)
and /work/SRC/openSUSE:Factory/.python-jwcrypto.new.1631729 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "python-jwcrypto"
Fri Oct 2 23:01:51 2026 rev:22 rq:1381872 version:1.6.1
Changes:
--------
--- /work/SRC/openSUSE:Factory/python-jwcrypto/python-jwcrypto.changes
2026-09-07 11:30:37.209710846 +0200
+++
/work/SRC/openSUSE:Factory/.python-jwcrypto.new.1631729/python-jwcrypto.changes
2026-10-02 23:02:19.537736001 +0200
@@ -1,0 +2,10 @@
+Wed Sep 30 13:18:21 UTC 2026 - Nico Krapp <[email protected]>
+
+- Update to 1.6.1 (fixes CVE-2026-92091 (bsc#1280816))
+ * Avoid quadratic duplicate check on JWK key_ops by @lissy93
+ in #398
+ * Loop optimizations by @rjeffman in #397
+ * Simplify key_ops checks by @simo5 in #399
+ * Version 1.6.1 by @simo5 in #400
+
+-------------------------------------------------------------------
Old:
----
jwcrypto-1.6.0.tar.gz
New:
----
jwcrypto-1.6.1.tar.gz
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Other differences:
------------------
++++++ python-jwcrypto.spec ++++++
--- /var/tmp/diff_new_pack.dBTNzO/_old 2026-10-02 23:02:20.808789200 +0200
+++ /var/tmp/diff_new_pack.dBTNzO/_new 2026-10-02 23:02:20.813789410 +0200
@@ -18,7 +18,7 @@
%{?sle15_python_module_pythons}
Name: python-jwcrypto
-Version: 1.6.0
+Version: 1.6.1
Release: 0
Summary: Python module package implementing JOSE Web standards
License: LGPL-3.0-only
@@ -47,7 +47,7 @@
RFC 7520 - Examples of Protecting Content Using JSON Object Signing and
Encryption (JOSE)
%prep
-%setup -q -n jwcrypto-%{version}
+%autosetup -p1 -n jwcrypto-%{version}
%build
%pyproject_wheel
++++++ jwcrypto-1.6.0.tar.gz -> jwcrypto-1.6.1.tar.gz ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore' old/jwcrypto-1.6.0/PKG-INFO new/jwcrypto-1.6.1/PKG-INFO
--- old/jwcrypto-1.6.0/PKG-INFO 2026-09-01 15:09:36.408043000 +0200
+++ new/jwcrypto-1.6.1/PKG-INFO 2026-09-15 23:22:24.280162300 +0200
@@ -1,6 +1,6 @@
Metadata-Version: 2.4
Name: jwcrypto
-Version: 1.6.0
+Version: 1.6.1
Summary: Implementation of JOSE Web standards
Home-page: https://github.com/latchset/jwcrypto
Maintainer: JWCrypto Project Contributors
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore' old/jwcrypto-1.6.0/jwcrypto/jwk.py
new/jwcrypto-1.6.1/jwcrypto/jwk.py
--- old/jwcrypto-1.6.0/jwcrypto/jwk.py 2026-09-01 15:09:21.000000000 +0200
+++ new/jwcrypto-1.6.1/jwcrypto/jwk.py 2026-09-15 23:22:04.000000000 +0200
@@ -247,6 +247,16 @@
'deriveBits': 'Derive bits not to be used as a key'}
"""Registry of allowed operations"""
+# Key Operations registry but augmented with use pair matching.
+JWKOpAndUsePairs = {'sign': 'sig',
+ 'verify': 'sig',
+ 'encrypt': 'enc',
+ 'decrypt': 'enc',
+ 'wrapKey': 'enc',
+ 'unwrapKey': 'enc',
+ 'deriveKey': 'enc',
+ 'deriveBits': 'enc'}
+
JWKpycaCurveMap = {'secp256r1': 'P-256',
'secp384r1': 'P-384',
'secp521r1': 'P-521',
@@ -707,28 +717,16 @@
# check key_ops
if 'key_ops' in newkey:
- for ko in newkey['key_ops']:
- cnt = 0
- for cko in newkey['key_ops']:
- if ko == cko:
- cnt += 1
- if cnt != 1:
- raise InvalidJWKValue('Duplicate values in "key_ops"')
-
- # check use/key_ops consistency
- if 'use' in newkey and 'key_ops' in newkey:
- sigl = ['sign', 'verify']
- encl = ['encrypt', 'decrypt', 'wrapKey', 'unwrapKey',
- 'deriveKey', 'deriveBits']
- if newkey['use'] == 'sig':
- for op in encl:
- if op in newkey['key_ops']:
- raise InvalidJWKValue('Incompatible "use" and'
- ' "key_ops" values specified at'
- ' the same time')
- elif newkey['use'] == 'enc':
- for op in sigl:
- if op in newkey['key_ops']:
+ if len(newkey['key_ops']) > len(JWKOperationsRegistry):
+ raise InvalidJWKValue('Unknown or duplicate "key_ops" values')
+
+ if len(set(newkey['key_ops'])) != len(newkey['key_ops']):
+ raise InvalidJWKValue('Duplicate values in "key_ops"')
+
+ # check use/key_ops consistency
+ if 'use' in newkey:
+ for op in newkey['key_ops']:
+ if newkey['use'] != JWKOpAndUsePairs.get(op, 'bad'):
raise InvalidJWKValue('Incompatible "use" and'
' "key_ops" values specified at'
' the same time')
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore' old/jwcrypto-1.6.0/jwcrypto/jwt.py
new/jwcrypto-1.6.1/jwcrypto/jwt.py
--- old/jwcrypto-1.6.0/jwcrypto/jwt.py 2026-09-01 15:09:21.000000000 +0200
+++ new/jwcrypto-1.6.1/jwcrypto/jwt.py 2026-09-15 23:22:04.000000000 +0200
@@ -535,12 +535,8 @@
cclaims = value
else:
cclaims = [value]
- found = False
- for v in cclaims:
- if v in tclaims:
- found = True
- break
- if not found:
+ token_audiences = set(tclaims)
+ if not any(v in token_audiences for v in cclaims):
raise JWTInvalidClaimValue(
"Invalid '{}' value. Expected '{}' in '{}'".format(
name, claims[name], value))
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore' old/jwcrypto-1.6.0/jwcrypto/tests.py
new/jwcrypto-1.6.1/jwcrypto/tests.py
--- old/jwcrypto-1.6.0/jwcrypto/tests.py 2026-09-01 15:09:21.000000000
+0200
+++ new/jwcrypto-1.6.1/jwcrypto/tests.py 2026-09-15 23:22:04.000000000
+0200
@@ -685,6 +685,11 @@
with self.assertRaises(jwk.InvalidJWKValue):
jwk.JWK(kty='oct', k=b'\x01')
+ def test_key_ops_duplicates(self):
+ jwk.JWK(kty='oct', k='AAAA', key_ops=['sign', 'verify'])
+ with self.assertRaises(jwk.InvalidJWKValue):
+ jwk.JWK(kty='oct', k='AAAA', key_ops=['sign', 'verify', 'sign'])
+
def test_create_pubKeys_eddsa(self):
keylist = PublicKeys_EdDsa['keys']
for key in keylist:
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore' old/jwcrypto-1.6.0/jwcrypto/version.py
new/jwcrypto-1.6.1/jwcrypto/version.py
--- old/jwcrypto-1.6.0/jwcrypto/version.py 2026-09-01 15:09:21.000000000
+0200
+++ new/jwcrypto-1.6.1/jwcrypto/version.py 2026-09-15 23:22:04.000000000
+0200
@@ -1 +1 @@
-__version__ = "1.6.0"
+__version__ = "1.6.1"
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn'
'--exclude=.svnignore' old/jwcrypto-1.6.0/jwcrypto.egg-info/PKG-INFO
new/jwcrypto-1.6.1/jwcrypto.egg-info/PKG-INFO
--- old/jwcrypto-1.6.0/jwcrypto.egg-info/PKG-INFO 2026-09-01
15:09:36.000000000 +0200
+++ new/jwcrypto-1.6.1/jwcrypto.egg-info/PKG-INFO 2026-09-15
23:22:24.000000000 +0200
@@ -1,6 +1,6 @@
Metadata-Version: 2.4
Name: jwcrypto
-Version: 1.6.0
+Version: 1.6.1
Summary: Implementation of JOSE Web standards
Home-page: https://github.com/latchset/jwcrypto
Maintainer: JWCrypto Project Contributors