PT-2026-103622 · Pypi · Pyjwt

·

CVE-2026-103001

·

Published

2026-09-08

·

Updated

2026-10-01

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions PyJWT versions 2.11.0 through 2.13.0
Description The PyJWT. merge options() function can modify a mutable options mapping provided by the caller when verify signature is set to false. If an application reuses this modified mapping in subsequent decode() or decode complete() calls while setting verify signature to true, the mapping may retain false values for several registered claim checks, including expiration, not-before, issued-at, audience, issuer, subject, and JWT ID. This allows a signed token with invalid registered claims to be accepted even when signature verification is enabled. Applications that use a fresh options mapping for every call are not affected.
Recommendations Update PyJWT to a version later than 2.13.0. As a temporary mitigation, ensure a fresh options mapping is created for each call to decode() or decode complete() instead of reusing a mutable mapping.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15795
CVE-2026-103001

Affected Products

Pyjwt