PT-2026-102362 · Pypi · Pyjwt

·

CVE-2026-102270

·

Published

2026-09-28

·

Updated

2026-10-04

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions PyJWT versions prior to 2.14.0
Description The is pem format() function is affected by a regular expression issue where lazy PEM processing causes extensive backtracking. This happens when input resembling a certificate contains repeated BEGIN markers but lacks a matching END marker, leading to unbounded backtracking during the search for the end marker. This behavior allows an attacker to cause intensive CPU consumption.
Recommendations Update to version 2.14.0. As a temporary workaround, restrict the use of the is pem format() function when processing untrusted input.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102270
GHSA-JWRC-G2Q2-PQ5P
OPENSUSE-SU-2026:11994-1
PYSEC-2026-4148

Affected Products

Pyjwt