HMAC Vulnerability in PyJWT Affects JSON Web Token Security
CVE-2026-102273
7.4HIGH
What is CVE-2026-102273?
The PyJWT library, which implements JSON Web Token standards, has a vulnerability that allows attackers to forge tokens. This issue arises from the HMACAlgorithm.prepare_key method, which improperly handles public JWK containers as valid HMAC secrets. When applications permit both HMAC and asymmetric algorithms, an attacker can exploit this flaw by successfully using a known public key to create tokens with arbitrary authenticated claims. This security flaw has been addressed in version 2.14.0 of PyJWT.
Affected Version(s)
pyjwt >= 2.13.0, < 2.14.0
