The vendor explicitly identifies these products as affected by this CVE.
- openshift-lightspeed/lightspeed-ocp-rag-rhel9 as a component of OpenShift Lightspeed
- openshift-lightspeed/lightspeed-service-api-rhel9 as a component of OpenShift Lightspeed
- openshift-lightspeed/lightspeed-to-dataverse-exporter-rhel9 as a component of OpenShift Lightspeed
- rhaiis/vllm-cpu-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-tpu-rhel9 as a component of Red Hat AI Inference Server
- ansible-automation-platform-25/lightspeed-chatbot-rhel8 as a component of Red Hat Ansible Automation Platform 2
- ansible-automation-platform-26/controller-rhel9 as a component of Red Hat Ansible Automation Platform 2
- ansible-automation-platform/automation-dashboard-rhel9 as a component of Red Hat Ansible Automation Platform 2
- rhoai/odh-llama-stack-core-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- satellite/foreman-mcp-server-rhel9 as a component of Red Hat Satellite 6
- rhtas/segment-reporting-rhel9 as a component of Red Hat Trusted Artifact Signer
- Summary
- A missing verification step has been discovered in PyJWT. PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC.
- Remediation
- For details on how to apply this update, refer to Ansible Automation Platform documentation.
