SSRF Vulnerability in PyJWT JSON Web Token Implementation by PyJWT Developers
CVE-2026-48522

4.2MEDIUM

Key Information:

Vendor

Jpadilla

Status
Vendor
CVE Published:
28 May 2026

What is CVE-2026-48522?

A vulnerability has been identified in the PyJWT library, a popular JSON Web Token implementation in Python. In versions before 2.13.0, the PyJWKClient class accepts URIs without restrictions, exposing applications to potential SSRF attacks. If an application's JWK URL is controlled by untrusted sources, an attacker could exploit this flaw to read local files or trigger requests to FTP and other data URIs. This may lead to serious security breaches, including unauthorized access or token forgery. It is crucial for developers to upgrade to version 2.13.0 or later to mitigate these risks.

Affected Version(s)

pyjwt < 2.13.0

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.