PyJWT 是 JSON Web Token(JWT)标准的 Python 实现。在 2.14.0 版本之前,PyJWKClient 存在安全漏洞,原因是其未对重定向目标进行验证,以确保其处于 JWKS(JSON Web Key Set)的信任边界内。当配置的受信任 JWKS 端点返回由攻击者控制的响应并导致重定向时,PyJWKClient 会跟随重定向,并将重定向后的响应内容当作密钥材料进行消费。这可能导致转发凭据泄露,或验证密钥被恶意替换。该问题已在 2.14.0 版本中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102268 | 9.1 CRITICAL | PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip th |
| CVE-2026-102266 | 7.4 HIGH | PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation |
| CVE-2026-102271 | 7.4 HIGH | PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 |
| CVE-2026-102272 | 7.4 HIGH | PyJWT BOM Bypass |
| CVE-2026-102273 | 7.4 HIGH | PyJWT accepts public JWK containers as HMAC secrets |
| CVE-2026-102275 | 6.5 MEDIUM | PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion |
| CVE-2026-102274 | 5.9 MEDIUM | PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set |
| CVE-2026-101918 | 5.3 MEDIUM | PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.g |
| CVE-2026-101917 | 5.3 MEDIUM | PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (inc |
| CVE-2026-102265 | 5.3 MEDIUM | PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header |
| CVE-2026-102269 | 4.8 MEDIUM | PyJWT: Non-canonical signature segments enable raw-token revocation bypass |
| CVE-2026-102270 | 4.4 MEDIUM | PyJWT: ReDoS vulnerability when calling the `is_pem_format` function. |
No comments yet