PT-2026-102364 · Pypi · Pyjwt

·

CVE-2026-102272

·

Published

2026-09-09

·

Updated

2026-10-04

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions PyJWT versions 2.13.0 through 2.13.x
Description An issue exists in the HMACAlgorithm.prepare key() function within jwt/algorithms.py where the raw-JWK detector fails to normalize Unicode byte-order marks (BOM) before JSON validation. When a public JSON Web Key (JWK) is prefixed with a UTF-8 BOM and utilized in a mixed-algorithm verification path, it bypasses asymmetric-key detection and is incorrectly treated as the HMAC secret. This allows an attacker with knowledge of the public key to forge authenticated tokens.
Recommendations Update to version 2.14.0.

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15802
CVE-2026-102272
GHSA-R6X4-923Q-G947
OPENSUSE-SU-2026:11994-1
PYSEC-2026-4150

Affected Products

Pyjwt