PT-2026-102348 · Pypi · Pyjwt
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
PyJWT versions 2.0.0a1 through 2.14.9
Description
The
PyJWKClient.get signing key from jwt function and the jwt/api jwt.py implementation when verify signature=False are affected by an issue where the payload parser catches ValueError but fails to catch RecursionError. This occurs when a recursively nested payload controlled by an attacker is processed by json.loads. Because the exception handling does not account for this failure, an unauthenticated request can trigger an exception that may result in an HTTP 500 response.Recommendations
Update PyJWT to version 2.15.0.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pyjwt