{"id":"CVE-2026-103001","title":"PyJWT is a Python implementation of JSON Web Token standards","summary":"PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N","cwe":["CWE-471"],"vendor":"jpadilla","product":"pyjwt","affected":["pyjwt >= 2.11.0, <= 2.13.0"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T22:16:33.537","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103001","references":[{"url":"https://github.com/jpadilla/pyjwt/commit/0c87c8c8b1a74cac99ad8115f3050efcb7fbed35","label":"security-advisories@github.com"},{"url":"https://github.com/jpadilla/pyjwt/issues/679","label":"security-advisories@github.com"},{"url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-gvp8-978c-rx2q","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-gvp8-978c-rx2q"}],"tags":["nvd","cve.org","ghsa","pip"],"ingestedAt":"2026-09-30T22:27:27.820Z","aliases":["GHSA-gvp8-978c-rx2q"],"ecosystem":"pip","slug":"CVE-2026-103001","body":"## Overview\n\nPyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses that same mapping for a later decode() or decode_complete() call and changes verify_signature to true, the mapping can retain false values for expiration, not-before, issued-at, audience, issuer, subject, and JWT ID checks. A signed token with invalid registered claims can then be accepted without disabling signature verification, but applications that create a fresh options mapping for each call are not affected.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-103001)\n\nAffected packages:\n\n- `PyJWT >= 2.11.0, <= 2.13.0`\n\nSource: https://github.com/advisories/GHSA-gvp8-978c-rx2q","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}