Recursion Error in PyJWT Affects JSON Web Token Handling
CVE-2026-101918
5.3MEDIUM
What is CVE-2026-101918?
The PyJWT library, which is a Python implementation of JSON Web Token standards, has a known vulnerability related to its error-handling mechanism. Specifically, in versions ranging from 2.0.0a1 to 2.14.0, the method PyJWKClient.get_signing_key_from_jwt fails to properly manage a RecursionError when a maliciously crafted payload is used. This payload can be recursively nested to trigger a value error, ultimately bypassing the library’s existing exception handling and leading to the potential for an HTTP 500 response from the server. This flaw is addressed in version 2.15.0, making it essential for users to upgrade to this version to mitigate risk.
Affected Version(s)
pyjwt >= 2.0.0a1, < 2.15.0
