SSRF Vulnerability in PyJWT JSON Web Token Implementation by PyJWT Developers
CVE-2026-48522
4.2MEDIUM
What is CVE-2026-48522?
A vulnerability has been identified in the PyJWT library, a popular JSON Web Token implementation in Python. In versions before 2.13.0, the PyJWKClient class accepts URIs without restrictions, exposing applications to potential SSRF attacks. If an application's JWK URL is controlled by untrusted sources, an attacker could exploit this flaw to read local files or trigger requests to FTP and other data URIs. This may lead to serious security breaches, including unauthorized access or token forgery. It is crucial for developers to upgrade to version 2.13.0 or later to mitigate these risks.
Affected Version(s)
pyjwt < 2.13.0
