Weakness in PyJWT Signature Processing in Affected Python Implementation
CVE-2026-102269
4.8MEDIUM
What is CVE-2026-102269?
PyJWT, a widely used Python library for JSON Web Token (JWT) standards, contains a vulnerability prior to version 2.14.0 that affects its signature segment processing. The issue arises because the decoding mechanism for the signature segment accepts characters outside of the expected Base64URL format. This flaw enables the possibility of appending non-Base64URL characters to a valid JWS signature segment, resulting in identical signature byte outcomes for distinct serialized segments. Consequently, this can lead to failures in token revocation checks, allowing unauthorized transactions or access with manipulated tokens. Users are strongly encouraged to upgrade to version 2.14.0 or later to mitigate this risk.
Affected Version(s)
pyjwt < 2.14.0
