Vulnerability in PyJWT Affects JSON Web Token Implementations
CVE-2026-102268

9.1CRITICAL

Key Information:

Vendor

Jpadilla

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-102268?

A vulnerability exists in PyJWT, a popular Python library for handling JSON Web Tokens, where the method is_pem_format does not effectively recognize all PEM formats accepted by the cryptography loader. This issue arises when applications improperly combine HMAC and asymmetric algorithms, providing a mutated public-key PEM as raw key bytes. Consequently, the HMACAlgorithm.prepare_key method mistakenly treats the unrecognized asymmetric public key as a legitimate HMAC secret, enabling an attacker with knowledge of the public key to forge authenticated HMAC tokens. This issue has been resolved in version 2.14.0.

Affected Version(s)

pyjwt < 2.14.0

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.