CVE-2026-85394 | mpdavis python-jose up to 3.5.0 HMAC initialization signature verification (EUVD-2026-70671 / Nessus ID 343059)
A vulnerability, which was classified as critical, has been found in mpdavis python-jose up to 3.5.0. This issue affects the function HMAC initialization. The manipulation leads to improper verification of cryptographic signature.
This vulnerability is uniquely identified as CVE-2026-85394. The attack is possible to be carried out remotely. No exploit exists.