Redirection Flaw in PyJWT Client Leads to Potential Credential Exposure
CVE-2026-102267
7.4HIGH
What is CVE-2026-102267?
A redirection flaw in PyJWT affects the PyJWKClient functionality, where redirect destinations are not properly validated against the JWKS trust boundary. This vulnerability allows an attacker to manipulate a trusted JWKS endpoint into issuing a malicious redirect, which can lead to the consumption of compromised key material and potentially expose sensitive credentials. The flaw was rectified in version 2.14.0.
Affected Version(s)
pyjwt < 2.14.0
