Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Tritsystem

#44093of 57,418
6.5Total CVSS
Vulnerabilities · 1
PT-2026-103622
6.5
2026-09-08
Pypi · Pyjwt · CVE-2026-103001
**Name of the Vulnerable Software and Affected Versions** PyJWT versions 2.11.0 through 2.13.0 **Description** The `PyJWT. merge options()` function can modify a mutable options mapping provided by the caller when `verify signature` is set to false. If an application reuses this modified mapping in subsequent `decode()` or `decode complete()` calls while setting `verify signature` to true, the mapping may retain false values for several registered claim checks, including expiration, not-before, issued-at, audience, issuer, subject, and JWT ID. This allows a signed token with invalid registered claims to be accepted even when signature verification is enabled. Applications that use a fresh options mapping for every call are not affected. **Recommendations** Update PyJWT to a version later than 2.13.0. As a temporary mitigation, ensure a fresh options mapping is created for each call to `decode()` or `decode complete()` instead of reusing a mutable mapping.