PT-2026-44398 · Pypi+1 · Pyjwt+1

·

CVE-2026-48526

·

Published

2026-05-28

·

Updated

2026-08-28

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions PyJWT versions prior to 2.13.0
Description PyJWT is a JSON Web Token implementation in Python. When the verifier decodes JSON Web Tokens while supporting both asymmetric and HMAC algorithms, the library fails to validate the use of JSON Web Keys in the HMAC algorithm. This allows an attacker to use the issuer public key as the secret key for the HMAC algorithm.
Recommendations Update to version 2.13.0.

Exploit

Fix

Improper Verification of Cryptographic Signature

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:25902
ALSA-2026:26206
AZL-93033
CLEANSTART-2026-AF67526
CLEANSTART-2026-AZ09261
CLEANSTART-2026-BY15343
CLEANSTART-2026-CQ05396
CLEANSTART-2026-EH47852
CLEANSTART-2026-EM82280
CLEANSTART-2026-EN66750
CLEANSTART-2026-FG72002
CLEANSTART-2026-FT24360
CLEANSTART-2026-FU68971
CLEANSTART-2026-GN02455
CLEANSTART-2026-HP19968
CLEANSTART-2026-IR98353
CLEANSTART-2026-JU43269
CLEANSTART-2026-LJ72726
CLEANSTART-2026-MJ28981
CLEANSTART-2026-MR94452
CLEANSTART-2026-NL78203
CLEANSTART-2026-QY59076
CLEANSTART-2026-RF67070
CLEANSTART-2026-SO50412
CLEANSTART-2026-UG08450
CLEANSTART-2026-UO85049
CLEANSTART-2026-UZ41796
CLEANSTART-2026-WQ85001
CLEANSTART-2026-WU03167
CVE-2026-48526
ECHO-B75B-8A3C-C7AE
GHSA-XGMM-8J9V-C9WX
OPENSUSE-SU-2026:11024-1
OPENSUSE-SU-2026:21095-1
PYSEC-2026-179
RHSA-2026:24069
RHSA-2026:25902
RHSA-2026:26206
RHSA-2026:34160
RHSA-2026:34365
RHSA-2026:35835
RHSA-2026:35836
RHSA-2026:35837
RHSA-2026:35845
RHSA-2026:50222
RHSA-2026:50223
RHSA-2026:50263
RHSA-2026:50319
RHSA-2026:50336
RHSA-2026:7634
SUSE-SU-2026:22138-1
SUSE-SU-2026:22170-1
SUSE-SU-2026:22220-1
SUSE-SU-2026:22238-1
SUSE-SU-2026:2626-1
SUSE-SU-2026:2627-1

Affected Products

Pyjwt
Rocky Linux