CVE-2024-33663: Python-Jose Project Python-Jose

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA keys and other key formats. This is similar to CVE-2022-29217.

Affected products

Published 2024-04-26. Last modified 2026-06-17.