Pypi · Pyjwt · CVE-2026-102270
**Name of the Vulnerable Software and Affected Versions**
PyJWT versions prior to 2.14.0
**Description**
The `is pem format()` function is affected by a regular expression issue where lazy PEM processing causes extensive backtracking. This happens when input resembling a certificate contains repeated BEGIN markers but lacks a matching END marker, leading to unbounded backtracking during the search for the end marker. This behavior allows an attacker to cause intensive CPU consumption.
**Recommendations**
Update to version 2.14.0.
As a temporary workaround, restrict the use of the `is pem format()` function when processing untrusted input.