Denial of Service Vulnerability in PyJWT by jpadilla
CVE-2026-102275
6.5MEDIUM
What is CVE-2026-102275?
PyJWT, a popular Python library for JSON Web Token standards, has a vulnerability affecting versions 2.1.0 through 2.15.0. The issue lies in the OKPAlgorithm.from_jwk method where the import path for private JWK does not adequately compare the public key derived from the private key. This flaw can lead to scenarios where an unauthorized entity could potentially use a stolen token without the legitimate private key, especially if an integration system fails to reject improper key parameters. To mitigate such risks, users are urged to upgrade to version 2.15.0, where this security concern has been addressed.
Affected Version(s)
pyjwt >= 2.1.0, < 2.15.0
