Skip to main content
Echelon
Graph
Product
Directory
Enterprise
Compliance
Pulse
Exposures
AI Analyst
Compare
Docs
Login
Start Free
Pulse
›
Vendor Advisories
›
Microsoft Security Response Center (MSRC)
›
CVE-2026-48522
CVE-2026-48522
Medium
CVSS
4.2
PyJWKClient: missing scheme allowlist enables SSRF + token forgery via file://, ftp://, data: schemes
Vendor
Microsoft Security Response Center (MSRC)
Published
July 27, 2026
Last Modified
—
🔗 CVE IDs covered (1)
CVE-2026-48522 →