[pkg-vuln] CVE-2026-48523 in pyjwt@2.12.1 #535

Closed
opened 2026-07-10 01:31:28 +00:00 by kert · 1 comment
Owner

Severity: MEDIUM
Package: pyjwt @ 2.12.1
Fixed in: 2.13.0

PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked against the caller-supplied algorithms allow-list, but signature verification is performed with the algorithm bound to the PyJWK object instead of the header algorithm. An attacker who controls a registered JWK/JWKS private key can sign with a disallowed algorithm, adv

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-48523

**Severity:** MEDIUM **Package:** `pyjwt` @ `2.12.1` **Fixed in:** `2.13.0` PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked against the caller-supplied algorithms allow-list, but signature verification is performed with the algorithm bound to the PyJWK object instead of the header algorithm. An attacker who controls a registered JWK/JWKS private key can sign with a disallowed algorithm, adv **Reference:** https://nvd.nist.gov/vuln/detail/CVE-2026-48523
kert added this to the P21: Package Supply Chain — inventory, mirrors, drift, vuln scanning milestone 2026-07-10 01:31:28 +00:00
kert added the ciquality labels 2026-07-10 01:31:28 +00:00
Author
Owner

Not exploitable here. CVE-2026-48523 (allow-list bypass when decoding with a PyJWK key) requires passing PyJWK objects to jwt.decode(); we pass a plain secret string. The only JWT usage is src/api/deps.py (jwt.decode(..., secret, algorithms=["HS256"]) with a static shared secret) and src/api/routes/auth.py (jwt.encode(..., algorithm="HS256")). No PyJWK, PyJWKClient, JWKS endpoint, or RFC 7797 detached payloads anywhere in the codebase (grep clean).

Bumped anyway (defense in depth): pyjwt 2.12.1 → 2.13.0 in 65c31cf88f (uv.lock + pkg-manifest; pyproject floor raised for direct deps). Advisory link is in the issue body.

**Not exploitable here.** CVE-2026-48523 (allow-list bypass when decoding with a `PyJWK` key) requires passing `PyJWK` objects to `jwt.decode()`; we pass a plain secret string. The only JWT usage is `src/api/deps.py` (`jwt.decode(..., secret, algorithms=["HS256"])` with a static shared secret) and `src/api/routes/auth.py` (`jwt.encode(..., algorithm="HS256")`). No `PyJWK`, `PyJWKClient`, JWKS endpoint, or RFC 7797 detached payloads anywhere in the codebase (grep clean). **Bumped anyway** (defense in depth): `pyjwt` 2.12.1 → 2.13.0 in https://git.fhirworx.io/homelab/stack/commit/65c31cf88fd8de552a006859159790de468403fb (uv.lock + pkg-manifest; pyproject floor raised for direct deps). Advisory link is in the issue body.
kert closed this issue 2026-07-10 17:19:01 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: homelab/stack#535