PT-2026-102360 · Pypi · Pyjwt

·

CVE-2026-102268

·

Published

2026-09-10

·

Updated

2026-10-04

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions PyJWT versions prior to 2.14.0
Description The is pem format function in jwt/utils.py fails to recognize all PEM representations accepted by the cryptography loader. This occurs when an application uses both HMAC and asymmetric algorithms and provides a mutated public-key PEM as raw key bytes. Consequently, the HMACAlgorithm.prepare key() function treats the unrecognized asymmetric public key as an HMAC secret, allowing an attacker with knowledge of the public key to forge authenticated HMAC tokens.
Recommendations Update to version 2.14.0.

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15800
CVE-2026-102268
GHSA-FFC3-869F-JXW9
OPENSUSE-SU-2026:11994-1
PYSEC-2026-4145

Affected Products

Pyjwt