Vulnerability in PyJWT Affects JSON Web Token Implementations
CVE-2026-102268
9.1CRITICAL
What is CVE-2026-102268?
A vulnerability exists in PyJWT, a popular Python library for handling JSON Web Tokens, where the method is_pem_format does not effectively recognize all PEM formats accepted by the cryptography loader. This issue arises when applications improperly combine HMAC and asymmetric algorithms, providing a mutated public-key PEM as raw key bytes. Consequently, the HMACAlgorithm.prepare_key method mistakenly treats the unrecognized asymmetric public key as a legitimate HMAC secret, enabling an attacker with knowledge of the public key to forge authenticated HMAC tokens. This issue has been resolved in version 2.14.0.
Affected Version(s)
pyjwt < 2.14.0
