DoS Vulnerability in PyJWT Affects JSON Web Token Implementation by Auth0
CVE-2026-48525

5.3MEDIUM

Key Information:

Vendor

Jpadilla

Status
Vendor
CVE Published:
28 May 2026

What is CVE-2026-48525?

The vulnerability in PyJWT, affecting versions from 2.8.0 to 2.12.1, involves an inappropriate handling of detached JWS tokens when using the unencoded-payload option. The implementation allows an attacker to craft a malicious Base64URL payload segment that can lead to excessive CPU and memory resource consumption, ultimately causing a Denial of Service (DoS) condition. This situation arises because the decoding process is performed before enforcing the rules for detached payloads, enabling a remote client to exploit the API endpoint that verifies these tokens. The issue has been resolved in version 2.13.0.

Affected Version(s)

pyjwt >= 2.8.0, < 2.13.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.