PyJWT 是基于 JSON Web Token(JWT)标准的 Python 实现。在版本 2.14.0 之前,PyJWT 的签名段存在安全隐患:签名段解码过程允许接收超出标准 Base64URL 编码规范的字符。具体而言,当向一个合法的紧凑型 JWS(JSON Web Signature)签名段末尾附加非 Base64URL 规范的字符时,就会触发此问题。 其后果是,base64url_decode 函数会为不同序列化形式的签名段生成相同的签名字节。因此,在对原始令牌进行撤销检查时,系统可能无法识别出经过等价修
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102268 | 9.1 CRITICAL | PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip th |
| CVE-2026-102266 | 7.4 HIGH | PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation |
| CVE-2026-102267 | 7.4 HIGH | PyJWT: PyJWKClient follows redirects when fetching JWKS |
| CVE-2026-102271 | 7.4 HIGH | PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 |
| CVE-2026-102272 | 7.4 HIGH | PyJWT BOM Bypass |
| CVE-2026-102273 | 7.4 HIGH | PyJWT accepts public JWK containers as HMAC secrets |
| CVE-2026-102275 | 6.5 MEDIUM | PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion |
| CVE-2026-102274 | 5.9 MEDIUM | PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set |
| CVE-2026-101918 | 5.3 MEDIUM | PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.g |
| CVE-2026-101917 | 5.3 MEDIUM | PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (inc |
| CVE-2026-102265 | 5.3 MEDIUM | PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header |
| CVE-2026-102270 | 4.4 MEDIUM | PyJWT: ReDoS vulnerability when calling the `is_pem_format` function. |
No comments yet