HMAC Vulnerability in PyJWT Affects JSON Web Token Security
CVE-2026-102273

7.4HIGH

Key Information:

Vendor

Jpadilla

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-102273?

The PyJWT library, which implements JSON Web Token standards, has a vulnerability that allows attackers to forge tokens. This issue arises from the HMACAlgorithm.prepare_key method, which improperly handles public JWK containers as valid HMAC secrets. When applications permit both HMAC and asymmetric algorithms, an attacker can exploit this flaw by successfully using a known public key to create tokens with arbitrary authenticated claims. This security flaw has been addressed in version 2.14.0 of PyJWT.

Affected Version(s)

pyjwt >= 2.13.0, < 2.14.0

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.