PyJWT 是 JSON Web Token 标准的 Python 实现。在版本 2.14.0 之前,PyJWT 的 函数存在缺陷:当遇到未知的 (密钥标识符)时,若缺少负缓存(negative cache)或最小刷新间隔机制,将强制执行刷新操作。该问题出现在未认证的令牌重复使用同一个未知的 ,或使用缓存的 JWKS(JSON Web Key Set)中不存在的多个不同 值的情况下。每次缓存未命中都会导致 刷新 JWKS,从而使得攻击者可以通过构造特定流量,放大对配置的 JWKS 端点的出站请求。该问题已在 2.1
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102268 | 9.1 CRITICAL | PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip th |
| CVE-2026-102266 | 7.4 HIGH | PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation |
| CVE-2026-102267 | 7.4 HIGH | PyJWT: PyJWKClient follows redirects when fetching JWKS |
| CVE-2026-102271 | 7.4 HIGH | PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 |
| CVE-2026-102272 | 7.4 HIGH | PyJWT BOM Bypass |
| CVE-2026-102273 | 7.4 HIGH | PyJWT accepts public JWK containers as HMAC secrets |
| CVE-2026-102275 | 6.5 MEDIUM | PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion |
| CVE-2026-102274 | 5.9 MEDIUM | PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set |
| CVE-2026-101918 | 5.3 MEDIUM | PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.g |
| CVE-2026-102265 | 5.3 MEDIUM | PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header |
| CVE-2026-102269 | 4.8 MEDIUM | PyJWT: Non-canonical signature segments enable raw-token revocation bypass |
| CVE-2026-102270 | 4.4 MEDIUM | PyJWT: ReDoS vulnerability when calling the `is_pem_format` function. |
No comments yet