PT-2026-44397 · Pypi · Pyjwt

·

CVE-2026-48525

·

Published

2026-05-28

·

Updated

2026-08-04

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions PyJWT versions 2.8.0 through 2.12.1
Description When verifying detached JWS tokens using the unencoded-payload option ("b64": false, RFC 7797), the software performs Base64URL decoding of the compact-serialization payload segment before enforcing detached-payload rules. Because the decoded payload is later discarded and replaced with the caller-provided detached payload, the middle segment can be used as a work amplifier. A remote client can provide an arbitrarily large Base64URL payload segment, forcing excessive CPU work and memory allocations regardless of whether the signature is valid. This results in an unauthenticated Denial of Service (DoS) against any endpoint verifying detached JWS.
Recommendations Update to version 2.13.0.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-93042
CLEANSTART-2026-AF67526
CLEANSTART-2026-AZ09261
CLEANSTART-2026-BY15343
CLEANSTART-2026-CQ05396
CLEANSTART-2026-EH47852
CLEANSTART-2026-EM82280
CLEANSTART-2026-EN66750
CLEANSTART-2026-FG72002
CLEANSTART-2026-FT24360
CLEANSTART-2026-FU68971
CLEANSTART-2026-GN02455
CLEANSTART-2026-HP19968
CLEANSTART-2026-IR98353
CLEANSTART-2026-JU43269
CLEANSTART-2026-LJ72726
CLEANSTART-2026-MJ28981
CLEANSTART-2026-MR94452
CLEANSTART-2026-NL78203
CLEANSTART-2026-QY59076
CLEANSTART-2026-RF67070
CLEANSTART-2026-SO50412
CLEANSTART-2026-UG08450
CLEANSTART-2026-UO85049
CLEANSTART-2026-UZ41796
CLEANSTART-2026-WQ85001
CLEANSTART-2026-WU03167
CVE-2026-48525
ECHO-C303-C499-BCC4
GHSA-W7VC-732C-9M39
OPENSUSE-SU-2026:11024-1
OPENSUSE-SU-2026:21095-1
PYSEC-2026-178
RHSA-2026:24069
SUSE-SU-2026:22138-1
SUSE-SU-2026:22170-1
SUSE-SU-2026:22220-1
SUSE-SU-2026:22238-1
SUSE-SU-2026:2626-1
SUSE-SU-2026:2627-1

Affected Products

Pyjwt