[pkg-vuln] CVE-2026-102272 in pyjwt@2.13.0 #896

Open
opened 2026-09-30 06:01:58 +00:00 by kert · 0 comments
Owner

Severity: HIGH
Package: pyjwt @ 2.13.0
Fixed in: 2.14.0

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.prepare_key in jwt/algorithms.py is affected because raw-JWK detector does not normalize accepted Unicode byte-order marks before checking for JSON. This occurs when a public JWK is prefixed with a UTF-8 BOM and used in a mixed-algorithm verification path. As a result, public JWK bypasses asymmetric-key detection and becomes the HMAC secret. Consequently, an attacker who knows the public key can

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-102272

**Severity:** HIGH **Package:** `pyjwt` @ `2.13.0` **Fixed in:** `2.14.0` PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.prepare_key in jwt/algorithms.py is affected because raw-JWK detector does not normalize accepted Unicode byte-order marks before checking for JSON. This occurs when a public JWK is prefixed with a UTF-8 BOM and used in a mixed-algorithm verification path. As a result, public JWK bypasses asymmetric-key detection and becomes the HMAC secret. Consequently, an attacker who knows the public key can **Reference:** https://nvd.nist.gov/vuln/detail/CVE-2026-102272
kert added this to the P21: Package Supply Chain — inventory, mirrors, drift, vuln scanning milestone 2026-09-30 06:01:58 +00:00
kert added the qualityci labels 2026-09-30 06:01:58 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: homelab/stack#896