Pypi · Pyjwt · CVE-2026-102275
**Name of the Vulnerable Software and Affected Versions**
PyJWT versions 2.1.0 through 2.14.0
**Description**
The `OKPAlgorithm.from jwk` function in `jwt/algorithms.py` fails to compare the public key derived from `d` with `x` during the private-JWK import process. This occurs when an OKP private JWK provides non-corresponding `x` and `d` components, causing the identity derived from `x` to differ from operations performed with `d`. If an integration accepts private key parameters from a proof header without rejecting them, an attacker could potentially use a stolen sender-constrained token without possessing the legitimate private key.
**Recommendations**
Update to version 2.15.0.