PT-2026-103622 · Pypi · Pyjwt
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
PyJWT versions 2.11.0 through 2.13.0
Description
The
PyJWT. merge options() function can modify a mutable options mapping provided by the caller when verify signature is set to false. If an application reuses this modified mapping in subsequent decode() or decode complete() calls while setting verify signature to true, the mapping may retain false values for several registered claim checks, including expiration, not-before, issued-at, audience, issuer, subject, and JWT ID. This allows a signed token with invalid registered claims to be accepted even when signature verification is enabled. Applications that use a fresh options mapping for every call are not affected.Recommendations
Update PyJWT to a version later than 2.13.0.
As a temporary mitigation, ensure a fresh options mapping is created for each call to
decode() or decode complete() instead of reusing a mutable mapping.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pyjwt