Pypi · Pyjwt · CVE-2026-102272
**Name of the Vulnerable Software and Affected Versions**
PyJWT versions 2.13.0 through 2.13.x
**Description**
An issue exists in the `HMACAlgorithm.prepare key()` function within `jwt/algorithms.py` where the raw-JWK detector fails to normalize Unicode byte-order marks (BOM) before JSON validation. When a public JSON Web Key (JWK) is prefixed with a UTF-8 BOM and utilized in a mixed-algorithm verification path, it bypasses asymmetric-key detection and is incorrectly treated as the HMAC secret. This allows an attacker with knowledge of the public key to forge authenticated tokens.
**Recommendations**
Update to version 2.14.0.