The dependency future that is picked up by pywkest has a vulnerability that is not patched.
GHSA-xqrq-4mgf-ff32
That can cause scanning tools to warn about the use of this module
flask-of-oil v1.2.2
├── cachelib v0.9.0
├── flask v2.3.3 (*)
├── pyjwkest v1.4.2
│ ├── future v1.0.0
│ ├── pycryptodomex v3.22.0
│ ├── requests v2.32.2
│ │ ├── certifi v2025.4.26
│ │ ├── charset-normalizer v3.4.2
│ │ ├── idna v3.10
│ │ └── urllib3 v2.4.0
│ └── six v1.17.0