Fedora Python SciTokens Vulnerabilities Addressed in Recent Updates

Fedora Python SciTokens Vulnerabilities Addressed in Recent Updates

First seen 22 Mar 2026, 05:58 UTC Linuxsecurity 45.8

Article Content

Browse articles
ThreatCluster

On March 22, 2026, Fedora released updates for the python-scitokens library addressing several vulnerabilities. The updates include the removal of legacy parent SciToken chaining behavior, enhancements to path traversal validation, and fixes for SQL injection risks in KeyCache through parameterized queries. These vulnerabilities could potentially allow unauthorized access and data manipulation. The updates affect Fedora 42 and Fedora 43 users, with versions 1.9.7 being the latest. Users are advised to apply the updates using the 'dnf' package manager. The updates were made available following the identification of risks associated with sibling-path authorization bypass and SQL injection. The updates are critical for maintaining the security of systems utilizing the SciToken library. No active exploitation has been reported at this time.

Key Points: • Fedora released critical updates for python-scitokens on March 22, 2026. • Vulnerabilities addressed include SQL injection and path traversal issues. • Users are urged to update to version 1.9.7 using the 'dnf' package manager.

Timeline

2026-03-13
Updates for python-scitokens released by Derek Weitzel.
2026-03-22
Fedora announces updates for python-scitokens.