Malformed RSA Key Vulnerability in PyJWT by Jpadilla
CVE-2026-102274
5.9MEDIUM
What is CVE-2026-102274?
PyJWT, a Python library for JSON Web Tokens, has a vulnerability affecting versions 2.9.0 to 2.14.0 where it fails to properly handle malformed RSA keys in JWK Set. This flaw occurs if the JWK Set contains an invalid RSA key, leading to an error that can disrupt the entire PyJWKSet creation process. As a result, this may cause authentication failures or denial of service at the request level. Users are advised to upgrade to version 2.14.0 or later to mitigate this issue.
Affected Version(s)
pyjwt >= 2.9.0, < 2.14.0
