Ubuntu 22.04 — python-authlib — multiple vulnerabilities (5 CVEs) — patch and remediation guide
🟡 Medium ⏱ 10–30 min Last verified: 25 May 2026 Affected versions: Ubuntu 22.04 (jammy) 📖 ~4 min read • Source: Ubuntu Security Notice USN-8065-1 Related CVEs: CVE-2025-62706 CVE-2025-68158 CVE-2025-59420 CVE-2024-37568 CVE-2025-61920 Upstream summary: Millie Solem discovered that Authlib did not properly restrict algorithm selection during JWT verification, allowing HMAC verification with asymmetric public […]