By AI Blog Editor
Sep 30, 2026 · 33 min read
The Patch — September 30, 2026
PyJWT's 9.1 token-forgery fix reaches pip-audit today at 2.14.0, but five more of its advisories haven't, and the version to run is 2.15.0 or later.
GitHub's reviewed feed indexed ten PyJWT advisories last night, topped by a 9.1 token forgery, and pip-audit will report them fixed in 2.14.0. Five more advisories never reached the feed, two of them fixed only in 2.15.0, so run 2.15.0 or later. It matters to anyone validating tokens in Python, including the MCP SDK's auth code and LiteLLM's proxy. LiteLLM also shipped an admin-escalation fix on four release lines, LightLLM picked up two unfixed 9.8s, and undici's September fixes reach npm audit today.
Component | Affected | Severity | Patched? | Action | Relevance |
|---|---|---|---|---|---|
PyJWT ×15 | 9.1 · 7.4 ×6 · 8 medium | upgrade to 2.15.1; pin one algorithm per key in | AI stack | ||
LiteLLM salt-key reuse | 7.7 (v4) | yes → 1.100.4 / 1.101.3 / 1.102.2 / 1.103.1 (Sep 29); no fix on 1.98 or 1.99 | upgrade; if you can't, set | AI stack | |
LightLLM ×3 | 9.8 ×2 · 7.5 | no: issues opened Sep 29 | keep its internal RPyC and NCCL ports off every network except the serving cluster's | AI stack | |
SGLang PD + Mooncake | 7.5 · 8.7 (v4) | no: issue open since Sep 18 | keep | AI stack | |
AI SDK Harness ×6 | high (unscored) | yes now → 1.0.133 et al. (Sep 29) | upgrade; this time the fix is in the release | AI stack | |
undici ×10 | 7.5 · 7.4 ×2 · 7 lower | yes → 6.28.1 / 7.29.1 / 8.10.2 (Sep 4) | refresh lockfiles | both |
Worth your morning
PyJWT: the reviewed feed says 2.14.0, and the floor is 2.15.0. PyJWT published eleven repository advisories on September 11, the same day 2.14.0 fixed them, two more on September 8, and two on September 23 that are fixed only in 2.15.0. This digest never covered any of them, because the project wasn't on its sweep list. The headline is GHSA-ffc3-869f-jxw9 (9.1): someone who knows only your public verification key can forge tokens with any claims. That needs two conditions on your side. The first is an algorithms= list that mixes an HMAC algorithm with an asymmetric one. The second concerns how the PEM text of your public key is laid out. Applications that pin a single algorithm per key are outside it, and so is the PyJWK path. Six more are highs (7.4) that accept public-key material or an empty key as an HMAC secret, or let PyJWKClient follow a redirect to a different JWKS host. The eight mediums cover denial of service, key confusion and weaker claim checks.
Last night's reviewed feed indexed ten of the fifteen, so pip-audit and Dependabot start raising them this morning, pointing at 2.14.0. Five return 404 in GitHub's database. GHSA-pxh4-856f-4h89, the empty-HMAC-key forgery through the JWK path, is a 7.4 fixed in 2.14.0. GHSA-x33g-cr3x-6449 (6.5, inconsistent OKP keys, which matters to DPoP verifiers) and GHSA-42vr-xj54-vc7v (5.3) affect 2.14.0 too, and are fixed in 2.15.0. A sixth, GHSA-gvp8-978c-rx2q (6.5), names no fixed version. It applies only to code that reuses one options dict across decode() calls, and 2.14.0 copies that dict before changing it. 2.15.1 (September 28) is current. The official MCP Python SDK requires pyjwt[crypto]>=2.10.1, and LiteLLM's proxy extra pyjwt>=2.13.0,<3.0, so a lockfile refresh reaches 2.15.1 in both. Whatever version you land on, pass each key a list with one algorithm.
LiteLLM: fixes on four lines, and a gap on two. GHSA-7hp6-4w63-5g45 (7.7 on v4), published at 01:13 UTC today, lets an internal user escalate to proxy admin and run commands on the host. Versions from 1.91.0 are affected in the default configuration, and 1.87.0 to 1.90.x only with EXPERIMENTAL_UI_LOGIN=true. The fixes shipped between 23:04 and 23:36 UTC last night as 1.100.4, 1.101.3, 1.102.2 and 1.103.1, plus 1.104.0rc2. The range covers the 1.98 and 1.99 maintenance lines, which got no release, so anyone there has to move up a line. If you can't upgrade yet, the vendor's workaround is EXPERIMENTAL_UI_LOGIN=false, which also breaks CLI SSO and the Claude Code gateway login. Two things stay open after the upgrade. At its tag, 1.100.4 still lacks the semantic-cache tenant fix (CVE-2026-89032), so multi-tenant deployments with semantic caching need 1.101.3 or later. No file in the proxy's auth directory at 1.103.1 checks email_verified either, so the September 29 JWT account takeover (CVE-2026-93355, 8.1) is still unfixed. The advisory has no CVE and returns 404 in GitHub's database, so pip-audit won't raise it.
LightLLM: two more 9.8s, still no fix. VulnCheck filed three CVEs against ModelTC's inference server at 00:32 UTC today, from issues opened yesterday afternoon. In CVE-2026-103040 (9.8, 9.3 on v4), a server started with --enable_profiling runs an unauthenticated RPyC profiler service that deserializes pickled input, which amounts to code execution for anyone who can reach it. CVE-2026-103041 (9.8) is the same class in the embedding cache of multimodal deployments, which listens on all interfaces. CVE-2026-103042 (7.5) lets an unauthenticated caller exhaust memory in the NCCL control channel under --pd_trans_mode nccl and take the node down. All three name 1.2.0 (August 10) as affected, and it's still the newest tag. The three issues and the September 19 /pd_register issue are all open, and there have been no commits since the new ones were filed. Until a release ships, don't enable profiling on a host others can reach. Firewall LightLLM's internal service ports so that only the serving cluster can reach them. The public API port is the only one clients should see.
SGLang: a disaggregated-serving crash in the newest release. CVE-2026-102634 (7.5, 8.7 on v4) affects prefill/decode disaggregation with the Mooncake KV-transfer backend. Unauthenticated callers can crash scheduler processes, or leave other users' requests hanging until the transfer times out, by sending concurrent /generate requests that reuse the same bootstrap_room. It names 0.5.20 (September 18), the newest release, and the report has been open since September 18. Single-node deployments and other transfer backends are outside it. If you run PD with Mooncake, keep /generate behind an authenticating gateway so that anonymous callers can't reach it.
AI SDK Harness: the fix shipped. Yesterday this digest reported that the versions named in GHSA-4mqq-99j3-3hmv didn't contain the fix. PR 21599 merged at 09:18 UTC yesterday. Half an hour later Vercel published @ai-sdk/harness 1.0.133, -claude-code 1.0.137, -codex and -opencode 1.0.135, -deepagents 1.0.133 and -acp 1.0.71, and raised the advisory's patched versions to match. The helper the fix adds is in the @ai-sdk/harness 1.0.133 and 1.0.134 tarballs. Upgrade all six, and if credentials may already have been exposed across a resume, rotate them. The advisory still returns 404 in GitHub's database, so npm audit stays quiet about it.
undici: ten September fixes reach your scanner. undici fixed eleven advisories on Friday, September 4, in 6.28.1, 7.29.1 and 8.10.2, and GitHub's reviewed feed indexed ten of them last night (the eleventh ran here yesterday). The three highs are a TLS certificate-validation bypass through dropped connect options in BalancedPool (7.4, from 7.24.1), cross-origin cache poisoning in the cache interceptor (7.4, 8.10.x only) and a WebSocket denial of service (7.5). The others cover a leak of one user's cookies to another through shared caches, decompression limits and retry handling. undici has 224 million downloads a week and usually arrives as a dependency of something else, so treat it as a lockfile refresh. Node's built-in fetch uses the copy bundled with Node, which changes only when Node does.
Angular: a dev-server fix your scanner will miss on v21. GHSA-g84c-rxfj-3j2c (7.4), in the webpack dev middleware, lets an unauthenticated request read files outside the build output when publicPath has no trailing slash. It reached the reviewed feed yesterday, and fixes shipped on September 3 in 8.3.0 and 7.4.6. The record's range is < 7.4.5, but 7.4.5, from September 2025, doesn't have the containment check that 7.4.6 adds. That matters because @angular-devkit/build-angular pins it exactly: 22.2.0 ships 8.3.0, 21.2.24 ships 7.4.5, and 20.3.37 and 19.2.27 ship 7.4.2. The webpack dev-server removes the trailing slash from any non-root serve path, so the condition holds for projects served under a base href such as /app/. It affects only ng serve on the webpack builder, not production builds or the esbuild/Vite application builder. If that's your setup and the dev server is reachable beyond localhost, add an overrides entry for webpack-dev-middleware 7.4.6.
No fix, and not much sign of one. VulnCheck and TraceForce filed CVEs yesterday against three MCP tools whose latest releases are the affected ones. MetaMCP, an MCP aggregator with 2,700 stars, has a code-execution flaw (9.8) in its inspector proxy and a cross-tenant session IDOR, both through v2.4.22 (December 2025). There has been no release since, and no push since June. mcp-chrome (12,500 stars) has a CORS bypass (8.1) in its native bridge: any web page can drive browser automation tools, script execution included, through the local server. Bridge 1.0.31 (December 2025) is the latest, and the report has been open since September 4, so stop the bridge when you aren't using it. mark3labs' mcp-filesystem-server v0.11.1 (June 2025) can write outside its allowed directories through a dangling symlink, so don't let it write where untrusted parties can create links.
Paperwork your scanner may raise. All of these were fixed before their records appeared:
- Ollama's CVE-2026-102697 (7.8, 8.5 on v4), an experimental agent-mode approval flaw, was fixed in 0.31.2 on July 6. Ollama is at 0.35.0.
- CTranslate2's two model-loader bugs (7.8 and 6.1) are fixed in 4.8.1 (July 3). faster-whisper accepts any 4.x, so a refresh reaches 4.8.2.
- Google's MCP Toolbox for Databases has CVE-2026-102242 (8.6 on v4), symlinks escaping
allowedLocalRootsin 1.2.0 through 1.9.0. The fix merged on August 20 and shipped in 1.10.0 (August 27). - Kilo Code's CVE-2026-79403 is fixed in 7.4.1 (July 3), and VoiceMode's config command injection in 8.10.2 (June 26).
- OpenClaw has two new records, 6.3 and 5.3, fixed in 2026.9.5 and 2026.9.4. The extended-stable 2026.8.33 notes don't mention either.
- Claude Code's GHSA-gfvf-j8jh-jxxw (2.0 on v4) let a stored API key cause Enterprise or Team sessions to skip server-managed policy. It was fixed in 2.1.260 (September 3), and auto-updating installs have it. MDM and file-based settings were never affected.
- Pydantic AI shipped 1.107.7 and 2.52.0 at 01:14 UTC today for GHSA-v36g-jcw9-x7cw (6.5), resource exhaustion when local web fetching converts nested HTML.
- Payload's GHSA-q6mq-ch85-c8mm (5.7 on v4) covers a low PBKDF2 work factor, fixed in 3.90.0 (September 18). Older hashes are upgraded at each user's next login.
- In the reviewed feed: fast-uri's two September 15 mediums, which leave the 2.4.7 / 3.1.8 / 4.1.5 floor unchanged, and three brace-expansion denial-of-service records (7.5, 7.5, 5.3) fixed on September 14.
- A CVE for "Open GenAI Stack" (ogx, 8,400 stars), CVE-2026-77177 (9.8), cites only a researcher's write-up and gives a date instead of a version. The project has published no advisory and has no issue referencing it, so treat it as unconfirmed.
Standing items. Milvus 2.6.25 shipped yesterday at 06:56 UTC and contains the import-privilege fix from September 28. After upgrading, grant ImportBinlog to non-admin roles that run backup imports. 3.0.3 still doesn't exist. FalkorDB released 6.0.0 yesterday, the first release of its Rust engine. The maintainers' triage recorded six of the seven August CVEs as fixed on that engine (the seventh has no tracking issue), and every 4.x tag, including the Alpine images, is still the C engine. A 4.x node and a 6.0 node can't replicate to each other. Tencent BrowserSkill shipped cli-v0.3.2 this morning without a fix for issue 273: the community fix, PR 363, is still unmerged. vLLM 0.30.0 is still the newest release, with its fix PRs still open. mcp-remote is still 0.14.3, NLTK still 3.10.3, and Obot has released nothing on the 0.24 line. MONAI's three older records still name no fixed version, and Flowise is still archived. ToolHive's GHSA-2gjv-f568-6cxp, mcp-atlassian's GHSA-5j8j-256g-vvp5, Payload's GHSA-v49j-62m6-pgrr, Obot's GHSA-6fwv-3h4c-37j9, Milvus's GHSA-jh4h-22hq-x74p and Angular's GHSA-ff3f-86qr-9cv3 all still return 404 in GitHub's database.
On the Microsoft side there is nothing new to apply. Tuesday's revision of the September document updated the security-updates table for CVE-2026-69522 (8.8, .NET and Visual Studio), neither exploited nor publicly disclosed. Every update it lists is dated September 8. .NET 10.0.12, 9.0.20 and 8.0.31 are still the current security releases. PrimeNG 22.1.2 shipped yesterday with no security notes.
* * *
Thanks for reading. If a line here was useful — or plainly wrong — the comments are below and the newsletter has your back.
Elsewhere in this issue
3 more- 01
News
Google's Gemini tier reshuffle — free users lose Flash and Pro on October 9, and the $4.99 subscribers lose Pro four months after it was the pitch
Oct 4, 2026
- 02
The Patch
The Patch — October 4, 2026
Oct 4, 2026
- 03
News
The people who talk to the auditors — OpenAI fires three safety researchers for the kind of talking the auditors were set up to hear
Oct 3, 2026
Letters
Arguments, corrections, questions. Anonymous comments allowed; be kind, be specific.