PT-2026-102365 · Pypi · Pyjwt

·

CVE-2026-102273

·

Published

2026-09-28

·

Updated

2026-09-29

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions PyJWT versions 2.13.0 through 2.13.x
Description The HMACAlgorithm.prepare key() function is affected because the HMAC key guard only recognizes top-level public JSON Web Key (JWK) forms and fails to identify container representations. This occurs when an application supports both HMAC and asymmetric algorithms and passes a public JWK container as the raw key, leading the system to accept public asymmetric key material as the HMAC secret. An attacker with knowledge of the public key can exploit this to forge tokens with arbitrary authenticated claims.
Recommendations Update to version 2.14.0.

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102273
GHSA-W2CX-738M-MC7W

Affected Products

Pyjwt