VDB
Sign up
—

PYSEC-2026-1305

Improper Privilege Management in djangorestframework-simplejwt

Quick fix

PYSEC-2026-1305 — djangorestframework-simplejwt: upgrade to the fixed version with the command below.

pip install --upgrade 'djangorestframework-simplejwt>=5.5.1'

Details

djangorestframework-simplejwt before version 5.5.1 is vulnerable to information disclosure. A user can access web application resources even after their account has been disabled due to missing user validation checks via the for_user method.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/djangorestframework-simplejwt
Introduced in: 0Fixed in: 5.5.1
Fixpip install --upgrade 'djangorestframework-simplejwt>=5.5.1'

References