{"id":"PYSEC-2026-1305","summary":"Improper Privilege Management in djangorestframework-simplejwt","details":"djangorestframework-simplejwt before version 5.5.1 is vulnerable to information disclosure. A user can access web application resources even after their account has been disabled due to missing user validation checks via the for_user method.","aliases":["CVE-2024-22513","GHSA-5vcc-86wm-547q"],"modified":"2026-07-07T17:46:38.050980485Z","published":"2026-07-07T11:45:35.359828Z","references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-22513"},{"type":"WEB","url":"https://github.com/jazzband/djangorestframework-simplejwt/issues/779"},{"type":"WEB","url":"https://github.com/jazzband/djangorestframework-simplejwt/pull/872"},{"type":"WEB","url":"https://github.com/jazzband/djangorestframework-simplejwt/pull/873"},{"type":"WEB","url":"https://github.com/jazzband/djangorestframework-simplejwt/pull/891"},{"type":"WEB","url":"https://github.com/jazzband/djangorestframework-simplejwt/commit/14e8b2cf5fa0df954af82ff3926fa6d6c4ecf13e"},{"type":"WEB","url":"https://github.com/jazzband/djangorestframework-simplejwt/commit/1ad763bfe73936515aa4756263338c63866364c9"},{"type":"WEB","url":"https://github.com/jazzband/djangorestframework-simplejwt/commit/a2d0a0201b6123536ecf76cd4d0ec7389317d0a7"},{"type":"WEB","url":"https://github.com/dmdhrumilmistry/CVEs/tree/main/CVE-2024-22513"},{"type":"PACKAGE","url":"https://github.com/jazzband/djangorestframework-simplejwt"},{"type":"WEB","url":"https://github.com/jazzband/djangorestframework-simplejwt/blob/c791e987332ed5e22a86428160d6372b1d85ffae/rest_framework_simplejwt/tokens.py#L281"},{"type":"PACKAGE","url":"https://pypi.org/project/djangorestframework-simplejwt"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-5vcc-86wm-547q"}],"affected":[{"package":{"name":"djangorestframework-simplejwt","ecosystem":"PyPI","purl":"pkg:pypi/djangorestframework-simplejwt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.5.1"}]}],"versions":["1.0","1.1","1.2","1.2.1","1.3","1.4","1.5","1.5.1","2.0.0","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.1","3.0","3.1","3.2","3.2.1","3.2.2","3.2.3","3.3","4.0.0","4.1.0","4.1.1","4.1.2","4.1.3","4.1.4","4.1.5","4.2.0","4.3.0","4.4.0","4.5.0","4.6.0","4.7.0","4.7.1","4.7.2","4.8.0","5.0.0","5.1.0","5.2.0","5.2.1","5.2.2","5.3.0","5.3.1","5.4.0","5.5.0"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/djangorestframework-simplejwt/PYSEC-2026-1305.yaml"}}],"schema_version":"1.7.5"}