PT-2026-102366 · Pypi · Pyjwt

·

CVE-2026-102274

·

Published

2026-09-08

·

Updated

2026-10-01

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions PyJWT versions 2.9.0 through 2.13.x
Description PyJWT fails to handle a ValueError triggered by the RSAAlgorithm.from jwk() function in jwt/api jwk.py when processing malformed RSA JSON Web Key (JWK) components. If a JWK Set contains a single malformed RSA key among valid keys, the construction of the entire PyJWKSet is aborted. This can lead to authentication failures or request-level denial of service for applications relying on this process.
Recommendations Update to version 2.14.0.

Exploit

Fix

DoS

Improper Handling of Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15801
CVE-2026-102274
GHSA-W6J9-CWV2-H6WQ
PYSEC-2026-4152

Affected Products

Pyjwt