Denial of Service Vulnerability in PyJWT by Jpadilla
CVE-2026-102270
4.4MEDIUM
What is CVE-2026-102270?
The is_pem_format function in PyJWT prior to version 2.14.0 is susceptible to a denial of service vulnerability. This occurs due to excessive backtracking when processing malformed certificate-like inputs that contain repeated BEGIN markers without corresponding END markers. As a result, attackers can exploit this vulnerability to cause significant CPU consumption, which can degrade application performance or render services unavailable. Users are urged to upgrade to version 2.14.0 or later to mitigate this issue.
Affected Version(s)
pyjwt < 2.14.0
