CVE-2026-102265Medium· 5.3▾ SunlitPyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWS._load in jwt/api_jws.py is affected because parser catches ValueError but not RecursionError. This occurs when a deeply nested token header rea…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWS._load in jwt/api_jws.py is affected because parser catches ValueError but not RecursionError. This occurs when a deeply nested token header reaches json.loads. As a result, RecursionError escapes the documented PyJWT error hierarchy. Consequently, an unauthenticated malformed token can cause a request-level failure and HTTP 500. This issue is fixed in version 2.14.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102273High· 7.4PyJWT is a Python implementation of JSON Web Token standards
CVE-2026-102274Medium· 5.9PyJWT is a Python implementation of JSON Web Token standards
CVE-2026-102270Medium· 4.4PyJWT is a Python implementation of JSON Web Token standards
CVE-2026-102271High· 7.4PyJWT is a Python implementation of JSON Web Token standards
CVE-2026-102272High· 7.4PyJWT is a Python implementation of JSON Web Token standards
CVE-2026-102267High· 7.4PyJWT is a Python implementation of JSON Web Token standards