Pypi · Pyjwt · CVE-2026-103001
**Name of the Vulnerable Software and Affected Versions**
PyJWT versions 2.11.0 through 2.13.0
**Description**
The `PyJWT. merge options()` function can modify a mutable options mapping provided by the caller when `verify signature` is set to false. If an application reuses this modified mapping in subsequent `decode()` or `decode complete()` calls while setting `verify signature` to true, the mapping may retain false values for several registered claim checks, including expiration, not-before, issued-at, audience, issuer, subject, and JWT ID. This allows a signed token with invalid registered claims to be accepted even when signature verification is enabled. Applications that use a fresh options mapping for every call are not affected.
**Recommendations**
Update PyJWT to a version later than 2.13.0.
As a temporary mitigation, ensure a fresh options mapping is created for each call to `decode()` or `decode complete()` instead of reusing a mutable mapping.