forbidden
Install command:
brew install forbiddenBypass 4xx HTTP response status codes and more
https://github.com/ivan-sincek/forbidden
License: MIT
Development: Pull requests
Formula JSON API: /api/formula/forbidden.json
Formula code: forbidden.rb on GitHub
Bottle (binary package) installation support provided for:
| macOS on Apple Silicon |
golden gate | ✅ |
|---|---|---|
| tahoe | ✅ | |
| sequoia | ✅ | |
| Linux | ARM64 | ✅ |
| x86_64 | ✅ |
Current versions:
| stable | ✅ | 13.4 |
| head | ⚡️ | HEAD |
Revision: 8
Depends on:
| certifi | 2026.7.22 | Mozilla CA bundle for Python |
| cffi | 2.1.1 | C Foreign Function Interface for Python |
| cryptography | 50.0.1 | Cryptographic recipes and primitives for Python |
| curl | 8.22.0 | Get a file from an HTTP, HTTPS or FTP server |
| openssl@3 | 3.6.5 | Cryptography and SSL/TLS Toolkit |
| pycparser | 3.0 | C parser in Python |
| python@3.14 | 3.14.7 | Interpreted, interactive, object-oriented programming language |
Binaries:
forbidden,
stresser
Known vulnerabilities in the current version:
| GHSA-2gx3-rcp4-g85q (medium) | PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete... |
| GHSA-8wjv-2p76-3863 (medium) | PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header |
| GHSA-9j54-fg26-wv3r (high) | PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation |
| GHSA-9v7f-9g4p-ffgj (high) | PyJWT: PyJWKClient follows redirects when fetching JWKS |
| GHSA-ffc3-869f-jxw9 (critical) | PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/as... |
| GHSA-hxm8-2xgr-2p9m (medium) | PyJWT: Non-canonical signature segments enable raw-token revocation bypass |
| GHSA-p4g4-x82p-q773 (high) | PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard |
| GHSA-r6x4-923q-g947 (high) | PyJWT BOM Bypass |
| GHSA-w2cx-738m-mc7w (high) | PyJWT accepts public JWK containers as HMAC secrets |
| GHSA-w6j9-cwv2-h6wq (medium) | PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set |
Data from Homebrew/advisory-database. Run brew vulns forbidden for a live check.
Analytics:
| 30 days | 90 days | 365 days | |
|---|---|---|---|
| Installs | 5 | 49 | 374 |
| Installs on Request | 5 | 49 | 374 |
| Build Errors | 0 |