[pkg-vuln] CVE-2026-101918 in pyjwt@2.13.0 #910

Open
opened 2026-10-01 06:01:53 +00:00 by kert · 0 comments
Owner

Severity: MEDIUM
Package: pyjwt @ 2.13.0
Fixed in: 2.15.0

PyJWT is a Python implementation of JSON Web Token standards. From 2.0.0a1 until 2.15.0, PyJWT PyJWKClient.get_signing_key_from_jwt is affected because payload parser catches ValueError but not RecursionError. This occurs when an attacker-controlled recursively nested payload reaches json.loads. As a result, documented PyJWT exception handling does not contain the failure. Consequently, an unauthenticated request can raise an exception that may produce an HTTP 500 response. The advisory-defined

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-101918

**Severity:** MEDIUM **Package:** `pyjwt` @ `2.13.0` **Fixed in:** `2.15.0` PyJWT is a Python implementation of JSON Web Token standards. From 2.0.0a1 until 2.15.0, PyJWT PyJWKClient.get_signing_key_from_jwt is affected because payload parser catches ValueError but not RecursionError. This occurs when an attacker-controlled recursively nested payload reaches json.loads. As a result, documented PyJWT exception handling does not contain the failure. Consequently, an unauthenticated request can raise an exception that may produce an HTTP 500 response. The advisory-defined **Reference:** https://nvd.nist.gov/vuln/detail/CVE-2026-101918
kert added this to the P21: Package Supply Chain — inventory, mirrors, drift, vuln scanning milestone 2026-10-01 06:01:53 +00:00
kert added the qualityci labels 2026-10-01 06:01:53 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: homelab/stack#910