Weakness in PyJWT Signature Processing in Affected Python Implementation
CVE-2026-102269

4.8MEDIUM

Key Information:

Vendor

Jpadilla

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-102269?

PyJWT, a widely used Python library for JSON Web Token (JWT) standards, contains a vulnerability prior to version 2.14.0 that affects its signature segment processing. The issue arises because the decoding mechanism for the signature segment accepts characters outside of the expected Base64URL format. This flaw enables the possibility of appending non-Base64URL characters to a valid JWS signature segment, resulting in identical signature byte outcomes for distinct serialized segments. Consequently, this can lead to failures in token revocation checks, allowing unauthorized transactions or access with manipulated tokens. Users are strongly encouraged to upgrade to version 2.14.0 or later to mitigate this risk.

Affected Version(s)

pyjwt < 2.14.0

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.