HMAC Token Forgery Vulnerability in PyJWT Library by Auth0
CVE-2026-102266
7.4HIGH
What is CVE-2026-102266?
The PyJWT library, utilized for handling JSON Web Tokens in Python, has a security flaw in versions 2.13.0 and 2.14.0. The issue lies in the HMACAlgorithm.from_jwk method, which improperly handles the key validation process. When a trusted JSON Web Key (JWK) Set contains an oct entry with an empty key value, the PyJWK verification path allows an attacker to craft an HMAC token using the zero-length key. This vulnerability enables the creation of forged tokens that can carry arbitrary authenticated claims, posing significant security risks for applications depending on the PyJWT library. The vulnerability is addressed in version 2.14.0.
Affected Version(s)
pyjwt >= 2.13.0, < 2.14.0
