DoS Vulnerability in PyJWT Affects JSON Web Token Implementation by Auth0
CVE-2026-48525
5.3MEDIUM
What is CVE-2026-48525?
The vulnerability in PyJWT, affecting versions from 2.8.0 to 2.12.1, involves an inappropriate handling of detached JWS tokens when using the unencoded-payload option. The implementation allows an attacker to craft a malicious Base64URL payload segment that can lead to excessive CPU and memory resource consumption, ultimately causing a Denial of Service (DoS) condition. This situation arises because the decoding process is performed before enforcing the rules for detached payloads, enabling a remote client to exploit the API endpoint that verifies these tokens. The issue has been resolved in version 2.13.0.
Affected Version(s)
pyjwt >= 2.8.0, < 2.13.0
