PT-2026-102360 · Pypi · Pyjwt
CVSS v2.0
9.4
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
PyJWT versions prior to 2.14.0
Description
The
is pem format function in jwt/utils.py fails to recognize all PEM representations accepted by the cryptography loader. This occurs when an application uses both HMAC and asymmetric algorithms and provides a mutated public-key PEM as raw key bytes. Consequently, the HMACAlgorithm.prepare key() function treats the unrecognized asymmetric public key as an HMAC secret, allowing an attacker with knowledge of the public key to forge authenticated HMAC tokens.Recommendations
Update to version 2.14.0.
Exploit
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pyjwt