PT-2026-102347 · Pypi · Pyjwt
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
PyJWT versions prior to 2.14.0
Description
The
get signing key from jwt function is affected by a flaw where unknown kid (Key ID) values trigger forced refreshes of the JSON Web Key Set (JWKS) without a negative cache or minimum refresh interval. This happens when unauthenticated tokens use the same unknown kid or various kid values not present in the cached JWKS, causing the PyJWKClient to refresh the JWKS on every cache miss. This behavior allows attacker traffic to amplify outbound requests to the configured JWKS endpoint.Recommendations
Update to version 2.14.0.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pyjwt