CVE-2026-103001
- EPSS 0.24%
- Veröffentlicht 30.09.2026 21:15:12
- Zuletzt bearbeitet 08.10.2026 13:13:53
PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses that same ma...
CVE-2026-102275
- EPSS 0.14%
- Veröffentlicht 28.09.2026 21:17:15
- Zuletzt bearbeitet 06.10.2026 18:17:51
PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in jwt/algorithms.py is affected because private-JWK import path does not compare the public key derived from d with x. This occurs wh...
CVE-2026-102274
- EPSS 0.35%
- Veröffentlicht 28.09.2026 21:17:15
- Zuletzt bearbeitet 06.10.2026 18:25:21
PyJWT is a Python implementation of JSON Web Token standards. From 2.9.0 until 2.14.0, PyJWKSet does not catch the plain ValueError raised for malformed RSA JWK components by RSAAlgorithm.from_jwk in jwt/api_jwk.py. This occurs when a JWK Set contai...
CVE-2026-102273
- EPSS 0.18%
- Veröffentlicht 28.09.2026 21:17:15
- Zuletzt bearbeitet 06.10.2026 18:29:42
PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because HMAC key guard only recognizes top-level public JWK forms and misses container representations. This occurs wh...
CVE-2026-102272
- EPSS 0.19%
- Veröffentlicht 28.09.2026 21:17:15
- Zuletzt bearbeitet 06.10.2026 18:34:24
PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.prepare_key in jwt/algorithms.py is affected because raw-JWK detector does not normalize accepted Unicode byte-order marks before checking for JSON....
CVE-2026-102271
- EPSS 0.18%
- Veröffentlicht 28.09.2026 21:17:15
- Zuletzt bearbeitet 06.10.2026 18:36:16
PyJWT is a Python implementation of JSON Web Token standards. From 2.4.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because asymmetric-key guard relies on textual markers that are absent from DER encoding. This occurs when an applicati...
CVE-2026-102265
- EPSS 0.29%
- Veröffentlicht 28.09.2026 21:17:14
- Zuletzt bearbeitet 07.10.2026 20:57:14
PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWS._load in jwt/api_jws.py is affected because parser catches ValueError but not RecursionError. This occurs when a deeply nested token header reaches json.loa...
CVE-2026-102270
- EPSS 0.19%
- Veröffentlicht 28.09.2026 21:17:14
- Zuletzt bearbeitet 06.10.2026 18:46:19
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT is_pem_format is affected because lazy PEM regular expression backtracks extensively. This occurs when a certificate-like input contains repeated BEGIN markers witho...
CVE-2026-102269
- EPSS 0.2%
- Veröffentlicht 28.09.2026 21:17:14
- Zuletzt bearbeitet 06.10.2026 18:54:08
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT signature segment is affected because signature segment decoding accepts characters outside the canonical Base64URL representation. This occurs when non-Base64URL ch...
CVE-2026-102268
- EPSS 0.2%
- Veröffentlicht 28.09.2026 21:17:14
- Zuletzt bearbeitet 07.10.2026 20:25:03
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected because is_pem_format does not recognize every PEM representation accepted by the cryptography loader. This occurs when an applic...