Pypi · Pyjwt · CVE-2026-101918
**Name of the Vulnerable Software and Affected Versions**
PyJWT versions 2.0.0a1 through 2.14.9
**Description**
The `PyJWKClient.get signing key from jwt` function and the `jwt/api jwt.py` implementation when `verify signature=False` are affected by an issue where the payload parser catches `ValueError` but fails to catch `RecursionError`. This occurs when a recursively nested payload controlled by an attacker is processed by `json.loads`. Because the exception handling does not account for this failure, an unauthenticated request can trigger an exception that may result in an HTTP 500 response.
**Recommendations**
Update PyJWT to version 2.15.0.