pyjwt是美国José Padilla个人开发者的一个 Python 库。允许对 JSON Web 令牌(JWT)进行编码和解码。 pyjwt 2.13.0之前版本存在安全漏洞,该漏洞源于PyJWKClient.get_signing_key()对每个具有未知kid值的JWT强制向JWKS端点发起新的HTTP请求,且无速率限制,导致攻击者可以触发无限制的出站请求。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48526 | 7.4 HIGH | PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed famil |
| CVE-2026-48523 | 5.4 MEDIUM | PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys |
| CVE-2026-48525 | 5.3 MEDIUM | PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b |
| CVE-2026-48522 | 4.2 MEDIUM | PyJWKClient: missing scheme allowlist enables SSRF + token forgery via file://, ftp://, da |
No comments yet