PyJWT 是 JSON Web Token 标准的 Python 实现。在 2.14.0 版本之前,jwt/utils.py 中的 is_pem_format 函数存在缺陷,因为它无法识别 cryptography 加载器所接受的所有 PEM 格式。当应用程序混合使用 HMAC 和非对称算法,并将经过篡改的非对称公钥以原始字节形式提供时,就会触发此问题。结果是,HMACAlgorithm.prepare_key 会将无法识别的非对称公钥误当作 HMAC 密钥使用。因此,攻击者只要知道公钥,就可以伪造经过 HMAC
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102266 | 7.4 HIGH | PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation |
| CVE-2026-102267 | 7.4 HIGH | PyJWT: PyJWKClient follows redirects when fetching JWKS |
| CVE-2026-102271 | 7.4 HIGH | PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 |
| CVE-2026-102272 | 7.4 HIGH | PyJWT BOM Bypass |
| CVE-2026-102273 | 7.4 HIGH | PyJWT accepts public JWK containers as HMAC secrets |
| CVE-2026-102275 | 6.5 MEDIUM | PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion |
| CVE-2026-102274 | 5.9 MEDIUM | PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set |
| CVE-2026-101918 | 5.3 MEDIUM | PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.g |
| CVE-2026-101917 | 5.3 MEDIUM | PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (inc |
| CVE-2026-102265 | 5.3 MEDIUM | PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header |
| CVE-2026-102269 | 4.8 MEDIUM | PyJWT: Non-canonical signature segments enable raw-token revocation bypass |
| CVE-2026-102270 | 4.4 MEDIUM | PyJWT: ReDoS vulnerability when calling the `is_pem_format` function. |
No comments yet