chore(deps): [oracle-bigquery-mcp-agent] Update vulnerabilityAlerts to v50.0.2 [SECURITY] - #725
Open
renovate-bot wants to merge 1 commit into
Conversation
renovate-bot
force-pushed
the
renovate/oracle-bigquery-mcp-agent-vulnerabilityalerts
branch
2 times, most recently
from
September 30, 2026 21:17
a88db0b to
85fe26e
Compare
renovate-bot
force-pushed
the
renovate/oracle-bigquery-mcp-agent-vulnerabilityalerts
branch
from
October 1, 2026 08:54
85fe26e to
efeadfb
Compare
…o v50.0.2 [SECURITY]
renovate-bot
force-pushed
the
renovate/oracle-bigquery-mcp-agent-vulnerabilityalerts
branch
from
October 1, 2026 12:18
efeadfb to
1e9e82b
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
50.0.1→50.0.22.13.0→2.15.12.7.0→2.8.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
CVE-2026-69249 / GHSA-jwv3-5hgf-82ww / PYSEC-2026-3553
More information
Details
Summary
When resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbounded recursion and guarantees termination, an attacker-controlled certificate chain can lead the processing to easily take more than 5s to reject in testing. This amplification could form the basis for a resource exhaustion denial of service attack.
This work was completed by Trail of Bits as part of the Patch The Planet project in collaboration with OpenAI. The finding was identified primarily by the Codex coding agent, and manually reviewed before submission.
Details
The core issue arises in the recursive nature of
build_chain_inner, which does not de-duplicate against previously analyzed candidates.A sufficient patch is to track valid issuers, and to skip seen ones before recursing. By tracking valid issuers only, validation and custom extension-policy callbacks still run.
In testing, this fix removed the exponential blowup without breaking apparent correctness.
PoC
The following script benchmarks processing times for malicious cert chains.
Impact
This issue exposes an amplification pathway over data that in many applications may be user-controlled, leading to the possibility of a denial of service through resource exhaustion. As the correctness of validation is not affected, the integrity of a system cannot be compromised through this vector, only its availability.
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
CVE-2026-69248 / GHSA-m2h6-j472-rp4c / PYSEC-2026-3554
More information
Details
Summary
If an intermediate constrained CA permits the DNS name
foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of*.example.com, python-cryptography's verifier accepts which allows escaping outside of the permitted names.PoC
Impact
Acceptance of invalid certificate chain.
Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:PReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building
CVE-2026-69249 / GHSA-jwv3-5hgf-82ww / PYSEC-2026-3553
More information
Details
Summary
When resolving invalid certificate chains that include duplicate copies of self-signed certificates, the processing recursively invokes the same candidate, leading to an exponential blowup. Although the limitation that the chain depth cannot exceed a specified maximum depth prevents unbounded recursion and guarantees termination, an attacker-controlled certificate chain can lead the processing to easily take more than 5s to reject in testing. This amplification could form the basis for a resource exhaustion denial of service attack.
This work was completed by Trail of Bits as part of the Patch The Planet project in collaboration with OpenAI. The finding was identified primarily by the Codex coding agent, and manually reviewed before submission.
Details
The core issue arises in the recursive nature of
build_chain_inner, which does not de-duplicate against previously analyzed candidates.A sufficient patch is to track valid issuers, and to skip seen ones before recursing. By tracking valid issuers only, validation and custom extension-policy callbacks still run.
In testing, this fix removed the exponential blowup without breaking apparent correctness.
PoC
The following script benchmarks processing times for malicious cert chains.
Impact
This issue exposes an amplification pathway over data that in many applications may be user-controlled, leading to the possibility of a denial of service through resource exhaustion. As the correctness of validation is not affected, the integrity of a system cannot be compromised through this vector, only its availability.
Severity
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:NReferences
This data is provided by OSV and the PyPI Advisory Database (CC-BY 4.0).
python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
CVE-2026-69248 / GHSA-m2h6-j472-rp4c / PYSEC-2026-3554
More information
Details
Summary
If an intermediate constrained CA permits the DNS name
foo.example.com, and the leaf certificate has a wildcard in its DNS SAN of*.example.com, python-cryptography's verifier accepts which allows escaping outside of the permitted names.PoC
Impact
Acceptance of invalid certificate chain.
Severity
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:PReferences
This data is provided by OSV and the PyPI Advisory Database (CC-BY 4.0).
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
CVE-2026-69247 / GHSA-g6cj-pr64-35w5 / PYSEC-2026-3552
More information
Details
Summary
pkcs7_decrypt_der,pkcs7_decrypt_pem, andpkcs7_decrypt_smimereported theoutcome of decrypting a
RecipientInfo'sencryptedKeyin severaldistinguishable ways, one of which disclosed the exact length recovered from the
RSA operation. The same distinction was also observable by timing. An
application that decrypts attacker-supplied
EnvelopedDataand reflects theoutcome gives the attacker a Bleichenbacher oracle against the
content-encryption key.
Introduced in 44.0.0. Fixed in 50.0.0.
Details
Decryption ran as: RSA PKCS#1 v1.5 decrypt of
encryptedKey→ build an AEScipher from the result → AES-CBC decrypt and PKCS#7 unpad. Each stage failed
differently, with no RFC 3218 mitigation:
Decryption failedInvalid key size (N) for AES., disclosingNInvalid padding bytes.Case 1 is reachable only where the linked library lacks implicit rejection:
OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. On OpenSSL 3.2+, used in our wheels,
invalid padding instead returns a synthetic plaintext of
pseudorandom length, so the error channel does not distinguish conforming
ciphertexts.
Exploitation requires a service that auto-decrypts untrusted
EnvelopedDatamatching the victim certificate and answers adaptively at high volume, such as
an S/MIME gateway or mail filter.
Fix
Per RFC 3218, the content-encryption algorithm is now resolved before the
private key is used, so the expected key length is known in advance. If the RSA
decryption fails or recovers a key of the wrong length, a random key of the
expected length is substituted and decryption continues down an identical path.
All failures now report identically and perform the same work.
Not addressed by this fix
EnvelopedDatadoes not authenticate its content. Tampering withencryptedContentalone yields a CBC padding oracle that recovers plaintext atroughly 256 queries per byte, without recovering any key, on every backend. This
is a property of PKCS#7 rather than of this implementation, cannot be fixed in
the library, and is now documented.
Credit
Reported by @X1AOxiang.
Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
CVE-2026-69247 / GHSA-g6cj-pr64-35w5 / PYSEC-2026-3552
More information
Details
Summary
pkcs7_decrypt_der,pkcs7_decrypt_pem, andpkcs7_decrypt_smimereported theoutcome of decrypting a
RecipientInfo'sencryptedKeyin severaldistinguishable ways, one of which disclosed the exact length recovered from the
RSA operation. The same distinction was also observable by timing. An
application that decrypts attacker-supplied
EnvelopedDataand reflects theoutcome gives the attacker a Bleichenbacher oracle against the
content-encryption key.
Introduced in 44.0.0. Fixed in 50.0.0.
Details
Decryption ran as: RSA PKCS#1 v1.5 decrypt of
encryptedKey→ build an AEScipher from the result → AES-CBC decrypt and PKCS#7 unpad. Each stage failed
differently, with no RFC 3218 mitigation:
Decryption failedInvalid key size (N) for AES., disclosingNInvalid padding bytes.Case 1 is reachable only where the linked library lacks implicit rejection:
OpenSSL 3.0 and 3.1, LibreSSL, and BoringSSL. On OpenSSL 3.2+, used in our wheels,
invalid padding instead returns a synthetic plaintext of
pseudorandom length, so the error channel does not distinguish conforming
ciphertexts.
Exploitation requires a service that auto-decrypts untrusted
EnvelopedDatamatching the victim certificate and answers adaptively at high volume, such as
an S/MIME gateway or mail filter.
Fix
Per RFC 3218, the content-encryption algorithm is now resolved before the
private key is used, so the expected key length is known in advance. If the RSA
decryption fails or recovers a key of the wrong length, a random key of the
expected length is substituted and decryption continues down an identical path.
All failures now report identically and perform the same work.
Not addressed by this fix
EnvelopedDatadoes not authenticate its content. Tampering withencryptedContentalone yields a CBC padding oracle that recovers plaintext atroughly 256 queries per byte, without recovering any key, on every backend. This
is a property of PKCS#7 rather than of this implementation, cannot be fixed in
the library, and is now documented.
Credit
Reported by @X1AOxiang.
Severity
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:NReferences
This data is provided by OSV and the PyPI Advisory Database (CC-BY 4.0).
PyJWT: Algorithm allow-list bypass when decoding with
PyJWK/PyJWKClientkeysCVE-2026-48523 / GHSA-jq35-7prp-9v3f
More information
Details
PyJWT
2.9.0through2.12.1allows a verifier-side algorithm allow-list bypass whenjwt.decode()orjwt.decode_complete()are called with aPyJWKkey. The token headeralgis checked against the caller-suppliedalgorithmsallow-list, but signature verification is performed with the algorithm bound to thePyJWKobject instead of the header algorithm. An attacker who controls a registered JWK/JWKS private key can sign with a disallowed algorithm, advertise an allowed algorithm in the JWT header, and still be accepted. The issue affects the documentedPyJWKClient.get_signing_key_from_jwt(...)flow.Summary
PyJWT's
PyJWKverification path allows a verifier-side algorithm allow-list bypass.In affected versions, when a JWT is decoded with a
PyJWKobject, PyJWT verifies that the headeralgstring is present in the caller'salgorithms=[...]list, but it does not actually use the header algorithm to verify the signature. Instead, it verifies with the algorithm already bound to thePyJWKobject.This lets an attacker who controls a registered JWK/JWKS private key sign with a disallowed algorithm and have the token accepted as long as the JWT header advertises an allowed algorithm. This affects the documented
PyJWKClientusage flow and does not require any non-default flags or unsafe configuration.Details
In
jwt/api_jws.pyin2.12.1,_verify_signature()treatsPyJWKkeys differently from normal PEM/public-key inputs:This logic means:
algis checked only as a string against the caller-supplied allow-list.PyJWK, the actual verifier is not selected from the header algorithm.key.Algorithm, which is fixed when thePyJWKobject is created.PyJWKbinds its algorithm injwt/api_jwk.pyfrom the JWK'salgfield or from key-type defaults:So once a
PyJWKis constructed, the verifier uses thePyJWK's bound algorithm, not the JWT header algorithm.The issue is reachable through the documented JWKS flow. In
docs/usage.rst, the project documents:PyJWKClient.get_signing_key_from_jwt()returns aPyJWK, so this documented path is affected.This is not a "no-key forgery" issue. The attacker still needs control of an accepted JWK/JWKS private key. However, that is realistic in deployments such as:
In those cases, the attacker can bypass verifier-side algorithm policy. For example, if the server intends to only accept
PS256, an attacker controlling an accepted RSA JWK can sign withRS256, setalg=PS256in the JWT header, and still be accepted through thePyJWKpath.The same forged token is rejected through the normal PEM/public-key verification path, which shows the bug is specific to
PyJWKverification rather than expected JWT behavior.This behavior was introduced by commit
ab8176abe21e550dbc1c9a6bb7e78ad80853bfb1(Decode with PyJWK (#​886)), which is present in tagged releases2.9.0,2.10.0,2.10.1,2.11.0,2.12.0, and2.12.1.PoC
Tested locally against PyJWT
2.12.1on Python3.12.10withcryptography 45.0.6.Install dependencies:
Run the following script:
Observed output:
The token is accepted when the verification key is a
PyJWK, even though:["RS512"]RS256The same token is rejected when verified through the normal PEM/public-key path.
Impact
This is an algorithm allow-list bypass affecting
jwt.decode()andjwt.decode_complete()when the verification key is aPyJWK, including keys returned byPyJWKClient.The impact depends on the deployment model:
Impacted deployments include:
algorithms=[...]to enforce a crypto policy against externally controlled signing keysWhat an attacker can do:
PS256" or "onlyRS512"What this issue does not do by itself:
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS
CVE-2026-48525 / GHSA-w7vc-732c-9m39
More information
Details
When verifying detached JWS tokens using the unencoded-payload option (
"b64": false, RFC 7797), PyJWT performs Base64URL decoding of the compact-serialization payload segment before enforcing the detached-payload rules.For
b64=false, PyJWT later discards that decoded payload and replaces it with the caller-provideddetached_payload. In practice, this turns the middle segment into an attacker-controlled “work amplifier”: a remote client can supply an arbitrarily large Base64URL payload segment that forces CPU work + memory allocations even if the signature is invalid.This creates an unauthenticated DoS vector against any endpoint that verifies detached JWS using PyJWT.
Affected Component(s)
jwt/api_jws.pyPyJWS.decode()/PyJWS.decode_complete()_load()(parsing and Base64URL decoding)Root Cause (exact logic flaw)
What happens in the code
In
jwt/api_jws.py,decode_complete()does the following (order matters):_load(jwt)first, which decodes the token segmentsheader.get("b64")and ifFalse, it replacespayload = detached_payloadand rebuilds the signing inputThis behavior is visible in
decode_complete():_load(jwt)happens before theb64=falsehandlingpayload = detached_payloadandsigning_input = ... detached_payloadhappens afterward ([GitHub][1])Inside
_load(), PyJWT unconditionally performs:payload = base64url_decode(payload_segment)This is the expensive step the attacker can amplify ([GitHub][1])
Why this becomes a vulnerability
For
b64=falsedetached JWS, the payload segment in compact form is effectively not needed for verification in PyJWT’s own logic (since the library usesdetached_payloadas the real payload). Yet PyJWT still decodes it first, meaning:Impact (evidence-driven)
Security impact
Standards context (RFC 7797)
RFC 7797 explicitly notes this option is used when payload is large and/or detached, and discusses interoperability requirements around marking it critical (“crit” with “b64”). ([IETF Datatracker][2])
(PyJWT supports
critvalidation, but the issue here is decode order / unbounded decode of an unused segment.)Affected Versions
(For GHSA, this phrasing is strong: “confirmed” + “likely since feature introduction”.)
Threat Model
Typical real deployment
A service verifies signed HTTP requests or webhooks using detached JWS:
detached_payloadAttacker
Attack chain
"b64": falseandcrit:["b64"].PyJWS.decode(...detached_payload=...).Proof of Concept - file names + results
PoC placement
server_localhost.py
client_localhost.py
flood_localhost.py
PoC # 1 - Localhost verification server
File: server_localhost.py
Purpose: real HTTP endpoint (
POST /verify) that calls PyJWT detached verification and prints:ok / time_ms / peak_bytes / token_len / error.Results (server console output)
Key takeaways from these results
At 8,000,000 chars, a single invalid-signature request still causes:
PoC # 2 - Localhost network client
File: client_localhost.py
Purpose: generates baseline + (invalid signature) + (valid signature) tokens and sends them over HTTP to localhost server.
Results (client output)
payload-chars = 500,000
payload-chars = 2,000,000
payload-chars = 8,000,000
Why this is strong evidence
PoC # 3 - Localhost flood / burst concurrency
File: flood_localhost.py
Purpose: sends N concurrent invalid-signature requests over HTTP to demonstrate queueing/worker starvation.
Results (your run: 20 concurrent @ 8,000,000 chars)