Denial of Service Vulnerability in PyJWT by jpadilla
CVE-2026-102275

6.5MEDIUM

Key Information:

Vendor

Jpadilla

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-102275?

PyJWT, a popular Python library for JSON Web Token standards, has a vulnerability affecting versions 2.1.0 through 2.15.0. The issue lies in the OKPAlgorithm.from_jwk method where the import path for private JWK does not adequately compare the public key derived from the private key. This flaw can lead to scenarios where an unauthorized entity could potentially use a stolen token without the legitimate private key, especially if an integration system fails to reject improper key parameters. To mitigate such risks, users are urged to upgrade to version 2.15.0, where this security concern has been addressed.

Affected Version(s)

pyjwt >= 2.1.0, < 2.15.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.