PT-2026-102365 · Pypi · Pyjwt
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
PyJWT versions 2.13.0 through 2.13.x
Description
The
HMACAlgorithm.prepare key() function is affected because the HMAC key guard only recognizes top-level public JSON Web Key (JWK) forms and fails to identify container representations. This occurs when an application supports both HMAC and asymmetric algorithms and passes a public JWK container as the raw key, leading the system to accept public asymmetric key material as the HMAC secret. An attacker with knowledge of the public key can exploit this to forge tokens with arbitrary authenticated claims.Recommendations
Update to version 2.14.0.
Exploit
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pyjwt