HMAC Token Forgery Vulnerability in PyJWT Library by Auth0
CVE-2026-102266

7.4HIGH

Key Information:

Vendor

Jpadilla

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-102266?

The PyJWT library, utilized for handling JSON Web Tokens in Python, has a security flaw in versions 2.13.0 and 2.14.0. The issue lies in the HMACAlgorithm.from_jwk method, which improperly handles the key validation process. When a trusted JSON Web Key (JWK) Set contains an oct entry with an empty key value, the PyJWK verification path allows an attacker to craft an HMAC token using the zero-length key. This vulnerability enables the creation of forged tokens that can carry arbitrary authenticated claims, posing significant security risks for applications depending on the PyJWT library. The vulnerability is addressed in version 2.14.0.

Affected Version(s)

pyjwt >= 2.13.0, < 2.14.0

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.