Pyjwt

Jpadilla · 22 CVEs

CVE-2026-103001
MEDIUM

PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse

Sep 30, 2026

CVE-2026-102275
HIGH

PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion

Sep 28, 2026

CVE-2026-102274
HIGH

PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set

Sep 28, 2026

CVE-2026-102273
HIGH

PyJWT accepts public JWK containers as HMAC secrets

Sep 28, 2026

CVE-2026-102272
HIGH

PyJWT BOM Bypass

Sep 28, 2026

CVE-2026-102271
HIGH

PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard

Sep 28, 2026

CVE-2026-102270
MEDIUM

PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.

Sep 28, 2026

CVE-2026-102269
MEDIUM

PyJWT: Non-canonical signature segments enable raw-token revocation bypass

Sep 28, 2026

CVE-2026-102268
CRITICAL

PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion gua…

Sep 28, 2026

CVE-2026-102267
CRITICAL

PyJWT: PyJWKClient follows redirects when fetching JWKS

Sep 28, 2026

CVE-2026-102266
CRITICAL

PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation

Sep 28, 2026

CVE-2026-102265
MEDIUM

PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header

Sep 28, 2026

CVE-2026-101918
HIGH

PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / ver…

Sep 28, 2026

CVE-2026-101917
HIGH

PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)

Sep 28, 2026

CVE-2026-48525
MEDIUM

PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS

May 28, 2026

CVE-2026-48523
MEDIUM

PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys

May 28, 2026

CVE-2026-48526
HIGH

PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed

May 28, 2026

CVE-2026-48524
MEDIUM

PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)

May 28, 2026

CVE-2026-48522
MEDIUM

PyJWKClient: missing scheme allowlist enables SSRF + token forgery via file://, ftp://, data: schemes

May 28, 2026

CVE-2026-32597
HIGH

PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)

Mar 12, 2026

CVE-2024-53861
LOW

Issuer field partial matches allowed in pyjwt

Nov 29, 2024

CVE-2022-29217
HIGH

Key confusion through non-blocklisted public key formats in PyJWT

May 24, 2022

Showing 1 to 22 of 22 CVEs