Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Wnsgurd90-Keke

#41112of 57,474
7.4Total CVSS
Vulnerabilities · 1
PT-2026-102364
7.4
2026-09-09
Pypi · Pyjwt · CVE-2026-102272
**Name of the Vulnerable Software and Affected Versions** PyJWT versions 2.13.0 through 2.13.x **Description** An issue exists in the `HMACAlgorithm.prepare key()` function within `jwt/algorithms.py` where the raw-JWK detector fails to normalize Unicode byte-order marks (BOM) before JSON validation. When a public JSON Web Key (JWK) is prefixed with a UTF-8 BOM and utilized in a mixed-algorithm verification path, it bypasses asymmetric-key detection and is incorrectly treated as the HMAC secret. This allows an attacker with knowledge of the public key to forge authenticated tokens. **Recommendations** Update to version 2.14.0.