Recursion Error in PyJWT Affects Token Processing
CVE-2026-102265
5.3MEDIUM
What is CVE-2026-102265?
The vulnerability in PyJWT affects versions from 2.13.0 to 2.14.0, where the PyJWS._load function does not properly handle RecursionError exceptions. This issue arises when a JSON Web Token with a deeply nested header is processed, leading to potential request-level failures and an HTTP 500 error. An unauthenticated malformed token can exploit this flaw, resulting in significant disruption. The problem has been addressed in version 2.14.0.
Affected Version(s)
pyjwt >= 2.13.0, < 2.14.0
