PT-2026-102361 · Pypi · Pyjwt
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PyJWT versions prior to 2.14.0
Description
PyJWT is a Python implementation of JSON Web Token standards. The signature segment decoding process accepts characters outside the canonical Base64URL representation when non-Base64URL characters are appended to a valid compact JWS signature segment. This causes the
base64url decode function to produce identical signature bytes for different serialized segments, which can lead to failures in raw-token revocation checks when attempting to recognize an equivalent modified token.Recommendations
Update PyJWT to version 2.14.0.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pyjwt