PyJWT 是 JSON Web Token 标准的 Python 实现。在版本 2.0.0a1 至 2.15.0 期间, 方法存在缺陷,因为其负载(payload)解析器捕获了 异常,但未捕获 (递归错误)。当攻击者控制的递归嵌套负载传入 时,会引发递归错误。由于文档中描述的 PyJWT 异常处理机制并未涵盖此失败场景,因此未经身份验证的请求可能触发异常,并导致返回 HTTP 500 服务器内部错误响应。 该漏洞公告所指出的受影响实现还包括 中设置 的情况。此问题已在版本 2.15.0 中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102268 | 9.1 CRITICAL | PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip th |
| CVE-2026-102266 | 7.4 HIGH | PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation |
| CVE-2026-102267 | 7.4 HIGH | PyJWT: PyJWKClient follows redirects when fetching JWKS |
| CVE-2026-102271 | 7.4 HIGH | PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 |
| CVE-2026-102272 | 7.4 HIGH | PyJWT BOM Bypass |
| CVE-2026-102273 | 7.4 HIGH | PyJWT accepts public JWK containers as HMAC secrets |
| CVE-2026-102275 | 6.5 MEDIUM | PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion |
| CVE-2026-102274 | 5.9 MEDIUM | PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set |
| CVE-2026-101917 | 5.3 MEDIUM | PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (inc |
| CVE-2026-102265 | 5.3 MEDIUM | PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header |
| CVE-2026-102269 | 4.8 MEDIUM | PyJWT: Non-canonical signature segments enable raw-token revocation bypass |
| CVE-2026-102270 | 4.4 MEDIUM | PyJWT: ReDoS vulnerability when calling the `is_pem_format` function. |
No comments yet