Pyjwt
Jpadilla · 22 CVEs
PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse
Sep 30, 2026
PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion
Sep 28, 2026
PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set
Sep 28, 2026
PyJWT accepts public JWK containers as HMAC secrets
Sep 28, 2026
PyJWT BOM Bypass
Sep 28, 2026
PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard
Sep 28, 2026
PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.
Sep 28, 2026
PyJWT: Non-canonical signature segments enable raw-token revocation bypass
Sep 28, 2026
PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion gua…
Sep 28, 2026
PyJWT: PyJWKClient follows redirects when fetching JWKS
Sep 28, 2026
PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation
Sep 28, 2026
PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header
Sep 28, 2026
PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / ver…
Sep 28, 2026
PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)
Sep 28, 2026
PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS
May 28, 2026
PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys
May 28, 2026
PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed
May 28, 2026
PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
May 28, 2026
PyJWKClient: missing scheme allowlist enables SSRF + token forgery via file://, ftp://, data: schemes
May 28, 2026
PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)
Mar 12, 2026
Issuer field partial matches allowed in pyjwt
Nov 29, 2024
Key confusion through non-blocklisted public key formats in PyJWT
May 24, 2022
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-103001 | PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse | MEDIUM | 0.24% | Sep 30, 2026 |
| CVE-2026-102275 | PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion | HIGH | 0.14% | Sep 28, 2026 |
| CVE-2026-102274 | PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set | HIGH | 0.39% | Sep 28, 2026 |
| CVE-2026-102273 | PyJWT accepts public JWK containers as HMAC secrets | HIGH | 0.18% | Sep 28, 2026 |
| CVE-2026-102272 | PyJWT BOM Bypass | HIGH | 0.18% | Sep 28, 2026 |
| CVE-2026-102271 | PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 guard | HIGH | 0.18% | Sep 28, 2026 |
| CVE-2026-102270 | PyJWT: ReDoS vulnerability when calling the `is_pem_format` function. | MEDIUM | 0.21% | Sep 28, 2026 |
| CVE-2026-102269 | PyJWT: Non-canonical signature segments enable raw-token revocation bypass | MEDIUM | 0.19% | Sep 28, 2026 |
| CVE-2026-102268 | PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard | CRITICAL | 0.20% | Sep 28, 2026 |
| CVE-2026-102267 | PyJWT: PyJWKClient follows redirects when fetching JWKS | CRITICAL | 0.16% | Sep 28, 2026 |
| CVE-2026-102266 | PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation | CRITICAL | 0.18% | Sep 28, 2026 |
| CVE-2026-102265 | PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header | MEDIUM | 0.29% | Sep 28, 2026 |
| CVE-2026-101918 | PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / verify_signature=False) | HIGH | 0.29% | Sep 28, 2026 |
| CVE-2026-101917 | PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524) | HIGH | 0.35% | Sep 28, 2026 |
| CVE-2026-48525 | PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS | MEDIUM | 0.41% | May 28, 2026 |
| CVE-2026-48523 | PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys | MEDIUM | 0.17% | May 28, 2026 |
| CVE-2026-48526 | PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed | HIGH | 0.43% | May 28, 2026 |
| CVE-2026-48524 | PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS) | MEDIUM | 0.32% | May 28, 2026 |
| CVE-2026-48522 | PyJWKClient: missing scheme allowlist enables SSRF + token forgery via file://, ftp://, data: schemes | MEDIUM | 0.22% | May 28, 2026 |
| CVE-2026-32597 | PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation) | HIGH | 0.28% | Mar 12, 2026 |
| CVE-2024-53861 | Issuer field partial matches allowed in pyjwt | LOW | 0.83% | Nov 29, 2024 |
| CVE-2022-29217 | Key confusion through non-blocklisted public key formats in PyJWT | HIGH | 1.35% | May 24, 2022 |
Showing 1 to 22 of 22 CVEs