python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-7036.json"