PT-2026-102373 · Pypi · Pyjwt
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
PyJWT versions 2.13.0 through 2.13.x
Description
The
PyJWS. load function in jwt/api jws.py fails to catch RecursionError when processing a deeply nested token header via json.loads. Because the parser only catches ValueError, the RecursionError bypasses the standard error handling hierarchy. This allows an unauthenticated attacker to send a malformed token that triggers a request-level failure, resulting in an HTTP 500 error.Recommendations
Update to version 2.14.0.
Exploit
Fix
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pyjwt