Fedora Security Advisories

scitokens-cpp-1.4.1-1.el10_3

2 hours ago
FEDORA-EPEL-2026-292969a0ee Packages in this update:
  • scitokens-cpp-1.4.1-1.el10_3
Update description:
  • Fix scope path boundary validation to deny sibling-prefix authorization bypasses
  • Reject parent-directory traversal in scope paths, including encoded traversal forms
  • Add regression tests covering sibling-prefix and traversal authorization checks

scitokens-cpp-1.4.1-1.el10_1

2 hours ago
FEDORA-EPEL-2026-5e624b43af Packages in this update:
  • scitokens-cpp-1.4.1-1.el10_1
Update description:
  • Fix scope path boundary validation to deny sibling-prefix authorization bypasses
  • Reject parent-directory traversal in scope paths, including encoded traversal forms
  • Add regression tests covering sibling-prefix and traversal authorization checks

scitokens-cpp-1.4.1-1.el8

2 hours ago
FEDORA-EPEL-2026-179159d77f Packages in this update:
  • scitokens-cpp-1.4.1-1.el8
Update description:
  • Fix scope path boundary validation to deny sibling-prefix authorization bypasses
  • Reject parent-directory traversal in scope paths, including encoded traversal forms
  • Add regression tests covering sibling-prefix and traversal authorization checks

scitokens-cpp-1.4.1-1.fc44

2 hours ago
FEDORA-2026-176625c3fc Packages in this update:
  • scitokens-cpp-1.4.1-1.fc44
Update description:
  • Fix scope path boundary validation to deny sibling-prefix authorization bypasses
  • Reject parent-directory traversal in scope paths, including encoded traversal forms
  • Add regression tests covering sibling-prefix and traversal authorization checks

scitokens-cpp-1.4.1-1.fc42

2 hours ago
FEDORA-2026-a6d1791c49 Packages in this update:
  • scitokens-cpp-1.4.1-1.fc42
Update description:
  • Fix scope path boundary validation to deny sibling-prefix authorization bypasses
  • Reject parent-directory traversal in scope paths, including encoded traversal forms
  • Add regression tests covering sibling-prefix and traversal authorization checks

scitokens-cpp-1.4.1-1.fc43

2 hours ago
FEDORA-2026-52c99ecf64 Packages in this update:
  • scitokens-cpp-1.4.1-1.fc43
Update description:
  • Fix scope path boundary validation to deny sibling-prefix authorization bypasses
  • Reject parent-directory traversal in scope paths, including encoded traversal forms
  • Add regression tests covering sibling-prefix and traversal authorization checks

scitokens-cpp-1.4.1-1.el9

2 hours ago
FEDORA-EPEL-2026-6d1034adaf Packages in this update:
  • scitokens-cpp-1.4.1-1.el9
Update description:
  • Fix scope path boundary validation to deny sibling-prefix authorization bypasses
  • Reject parent-directory traversal in scope paths, including encoded traversal forms
  • Add regression tests covering sibling-prefix and traversal authorization checks

python-scitokens-1.9.7-1.fc43

2 hours 12 minutes ago
FEDORA-2026-727b73bfa0 Packages in this update:
  • python-scitokens-1.9.7-1.fc43
Update description:
  • Remove legacy parent SciToken chaining behavior from token initialization and claim handling
  • Harden Enforcer scope path traversal validation (including encoded traversal checks)
  • Clean up documentation references to parent/chained SciTokens
  • Fix SQL injection risk in KeyCache by using parameterized SQLite queries
  • Prevent sibling-path authorization bypass in Enforcer scope checks

python-scitokens-1.9.7-1.el9

2 hours 12 minutes ago
FEDORA-EPEL-2026-f38b3ac925 Packages in this update:
  • python-scitokens-1.9.7-1.el9
Update description:
  • Remove legacy parent SciToken chaining behavior from token initialization and claim handling
  • Harden Enforcer scope path traversal validation (including encoded traversal checks)
  • Clean up documentation references to parent/chained SciTokens
  • Fix SQL injection risk in KeyCache by using parameterized SQLite queries
  • Prevent sibling-path authorization bypass in Enforcer scope checks

python-scitokens-1.9.7-1.el8

2 hours 12 minutes ago
FEDORA-EPEL-2026-9aaf8075c2 Packages in this update:
  • python-scitokens-1.9.7-1.el8
Update description:
  • Remove legacy parent SciToken chaining behavior from token initialization and claim handling
  • Harden Enforcer scope path traversal validation (including encoded traversal checks)
  • Clean up documentation references to parent/chained SciTokens
  • Fix SQL injection risk in KeyCache by using parameterized SQLite queries
  • Prevent sibling-path authorization bypass in Enforcer scope checks

python-scitokens-1.9.7-1.fc42

2 hours 12 minutes ago
FEDORA-2026-dec8f790f7 Packages in this update:
  • python-scitokens-1.9.7-1.fc42
Update description:
  • Remove legacy parent SciToken chaining behavior from token initialization and claim handling
  • Harden Enforcer scope path traversal validation (including encoded traversal checks)
  • Clean up documentation references to parent/chained SciTokens
  • Fix SQL injection risk in KeyCache by using parameterized SQLite queries
  • Prevent sibling-path authorization bypass in Enforcer scope checks

python-scitokens-1.9.7-1.fc44

2 hours 12 minutes ago
FEDORA-2026-86ad7d8a1a Packages in this update:
  • python-scitokens-1.9.7-1.fc44
Update description:
  • Remove legacy parent SciToken chaining behavior from token initialization and claim handling
  • Harden Enforcer scope path traversal validation (including encoded traversal checks)
  • Clean up documentation references to parent/chained SciTokens
  • Fix SQL injection risk in KeyCache by using parameterized SQLite queries
  • Prevent sibling-path authorization bypass in Enforcer scope checks

python-scitokens-1.9.7-1.el10_3

2 hours 12 minutes ago
FEDORA-EPEL-2026-ea5e5199eb Packages in this update:
  • python-scitokens-1.9.7-1.el10_3
Update description:
  • Remove legacy parent SciToken chaining behavior from token initialization and claim handling
  • Harden Enforcer scope path traversal validation (including encoded traversal checks)
  • Clean up documentation references to parent/chained SciTokens
  • Fix SQL injection risk in KeyCache by using parameterized SQLite queries
  • Prevent sibling-path authorization bypass in Enforcer scope checks

python-scitokens-1.9.6-1.fc44

5 hours 56 minutes ago
FEDORA-2026-88c19a9021 Packages in this update:
  • python-scitokens-1.9.6-1.fc44
Update description:
  • Fix SQL injection risk in KeyCache by using parameterized SQLite queries
  • Prevent sibling-path authorization bypass in Enforcer scope checks

python-scitokens-1.9.6-1.el10_3

5 hours 56 minutes ago
FEDORA-EPEL-2026-111290d799 Packages in this update:
  • python-scitokens-1.9.6-1.el10_3
Update description:
  • Fix SQL injection risk in KeyCache by using parameterized SQLite queries
  • Prevent sibling-path authorization bypass in Enforcer scope checks

python-scitokens-1.9.6-1.el9

5 hours 56 minutes ago
FEDORA-EPEL-2026-78ae7c544d Packages in this update:
  • python-scitokens-1.9.6-1.el9
Update description:
  • Fix SQL injection risk in KeyCache by using parameterized SQLite queries
  • Prevent sibling-path authorization bypass in Enforcer scope checks

python-scitokens-1.9.6-1.el8

5 hours 56 minutes ago
FEDORA-EPEL-2026-7d2cb4f270 Packages in this update:
  • python-scitokens-1.9.6-1.el8
Update description:
  • Fix SQL injection risk in KeyCache by using parameterized SQLite queries
  • Prevent sibling-path authorization bypass in Enforcer scope checks

python-scitokens-1.9.6-1.fc42

5 hours 56 minutes ago
FEDORA-2026-488d5c2f3a Packages in this update:
  • python-scitokens-1.9.6-1.fc42
Update description:
  • Fix SQL injection risk in KeyCache by using parameterized SQLite queries
  • Prevent sibling-path authorization bypass in Enforcer scope checks

python-scitokens-1.9.6-1.fc43

5 hours 56 minutes ago
FEDORA-2026-31c056f844 Packages in this update:
  • python-scitokens-1.9.6-1.fc43
Update description:
  • Fix SQL injection risk in KeyCache by using parameterized SQLite queries
  • Prevent sibling-path authorization bypass in Enforcer scope checks

python-ujson-5.12.0-1.el10_1

8 hours 56 minutes ago
FEDORA-EPEL-2026-fcc952d28d Packages in this update:
  • python-ujson-5.12.0-1.el10_1
Update description:

Update to 5.12.0. This release updates the license field in the Python metadata and fixes a buffer overflow/infinite loop from indent handling.

Checked
17 minutes 42 seconds ago