PyJWT 是 JSON Web Token(JWT)标准的 Python 实现。在 2.1.0 到 2.15.0 版本中, 中的 方法存在安全漏洞,原因是其在导入私用 JWK(JSON Web Key)时,未验证由私钥参数 推导出的公钥是否与 坐标一致。当提供的 OKP 类型私用 JWK 中 和 分量不匹配时,就会触发此问题。结果是,从 派生的身份可能与使用 执行的实际操作不一致。因此,如果应用程序集成过程中接受来自证明头(proof header)的私钥参数且未加以拒绝,攻击者就可能利用被盗发的、受发送者约束(
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102268 | 9.1 CRITICAL | PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip th |
| CVE-2026-102266 | 7.4 HIGH | PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation |
| CVE-2026-102267 | 7.4 HIGH | PyJWT: PyJWKClient follows redirects when fetching JWKS |
| CVE-2026-102271 | 7.4 HIGH | PyJWT: Public keys in DER form are accepted as HMAC secrets, bypassing the CVE-2022-29217 |
| CVE-2026-102272 | 7.4 HIGH | PyJWT BOM Bypass |
| CVE-2026-102273 | 7.4 HIGH | PyJWT accepts public JWK containers as HMAC secrets |
| CVE-2026-102274 | 5.9 MEDIUM | PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set |
| CVE-2026-101918 | 5.3 MEDIUM | PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.g |
| CVE-2026-101917 | 5.3 MEDIUM | PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (inc |
| CVE-2026-102265 | 5.3 MEDIUM | PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header |
| CVE-2026-102269 | 4.8 MEDIUM | PyJWT: Non-canonical signature segments enable raw-token revocation bypass |
| CVE-2026-102270 | 4.4 MEDIUM | PyJWT: ReDoS vulnerability when calling the `is_pem_format` function. |
No comments yet