[pkg-vuln] CVE-2026-48523 in pyjwt@2.12.1 #535
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Severity: MEDIUM
Package:
pyjwt@2.12.1Fixed in:
2.13.0PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked against the caller-supplied algorithms allow-list, but signature verification is performed with the algorithm bound to the PyJWK object instead of the header algorithm. An attacker who controls a registered JWK/JWKS private key can sign with a disallowed algorithm, adv
Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-48523
Not exploitable here. CVE-2026-48523 (allow-list bypass when decoding with a
PyJWKkey) requires passingPyJWKobjects tojwt.decode(); we pass a plain secret string. The only JWT usage issrc/api/deps.py(jwt.decode(..., secret, algorithms=["HS256"])with a static shared secret) andsrc/api/routes/auth.py(jwt.encode(..., algorithm="HS256")). NoPyJWK,PyJWKClient, JWKS endpoint, or RFC 7797 detached payloads anywhere in the codebase (grep clean).Bumped anyway (defense in depth):
pyjwt2.12.1 → 2.13.0 in65c31cf88f(uv.lock + pkg-manifest; pyproject floor raised for direct deps). Advisory link is in the issue body.