PT-2026-102350 · Pypi · Pyjwt

·

CVE-2026-102266

·

Published

2026-09-09

·

Updated

2026-09-29

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions PyJWT versions 2.13.0 through 2.13.x
Description The HMACAlgorithm.from jwk() function is affected because the PyJWK verification path uses the decoded key without applying prepare key validation. This occurs when a trusted JSON Web Key (JWK) Set contains an oct entry with an empty k variable. An attacker can sign an HMAC token using a zero-length key, allowing forged tokens to carry arbitrary authenticated claims.
Recommendations Update to version 2.14.0.

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15806
CVE-2026-102266
GHSA-9J54-FG26-WV3R

Affected Products

Pyjwt