Recursion Error in PyJWT Affects JSON Web Token Handling
CVE-2026-101918

5.3MEDIUM

Key Information:

Vendor

Jpadilla

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-101918?

The PyJWT library, which is a Python implementation of JSON Web Token standards, has a known vulnerability related to its error-handling mechanism. Specifically, in versions ranging from 2.0.0a1 to 2.14.0, the method PyJWKClient.get_signing_key_from_jwt fails to properly manage a RecursionError when a maliciously crafted payload is used. This payload can be recursively nested to trigger a value error, ultimately bypassing the library’s existing exception handling and leading to the potential for an HTTP 500 response from the server. This flaw is addressed in version 2.15.0, making it essential for users to upgrade to this version to mitigate risk.

Affected Version(s)

pyjwt >= 2.0.0a1, < 2.15.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.