PT-2026-102348 · Pypi · Pyjwt

·

CVE-2026-101918

·

Published

2026-09-28

·

Updated

2026-09-30

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions PyJWT versions 2.0.0a1 through 2.14.9
Description The PyJWKClient.get signing key from jwt function and the jwt/api jwt.py implementation when verify signature=False are affected by an issue where the payload parser catches ValueError but fails to catch RecursionError. This occurs when a recursively nested payload controlled by an attacker is processed by json.loads. Because the exception handling does not account for this failure, an unauthenticated request can trigger an exception that may result in an HTTP 500 response.
Recommendations Update PyJWT to version 2.15.0.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101918
GHSA-42VR-XJ54-VC7V

Affected Products

Pyjwt