Pypi · Pyjwt · CVE-2026-102267
**Name of the Vulnerable Software and Affected Versions**
PyJWT versions prior to 2.14.0
**Description**
The `PyJWKClient` component fails to revalidate redirect destinations against the JWKS trust boundary. When a trusted JWKS endpoint returns a redirect influenced by an attacker, the client follows it and processes the redirected response as key material. This can lead to the disclosure of forwarded credentials or the substitution of verification keys.
**Recommendations**
Update to version 2.14.0.