PT-2026-102347 · Pypi · Pyjwt

·

CVE-2026-101917

·

Published

2026-09-10

·

Updated

2026-10-04

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions PyJWT versions prior to 2.14.0
Description The get signing key from jwt function is affected by a flaw where unknown kid (Key ID) values trigger forced refreshes of the JSON Web Key Set (JWKS) without a negative cache or minimum refresh interval. This happens when unauthenticated tokens use the same unknown kid or various kid values not present in the cached JWKS, causing the PyJWKClient to refresh the JWKS on every cache miss. This behavior allows attacker traffic to amplify outbound requests to the configured JWKS endpoint.
Recommendations Update to version 2.14.0.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15805
CVE-2026-101917
GHSA-2GX3-RCP4-G85Q
OPENSUSE-SU-2026:11994-1
PYSEC-2026-4140

Affected Products

Pyjwt