---
id: CVE-2026-102269
title: PyJWT is a Python implementation of JSON Web Token standards
summary: >-
  PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0,
  PyJWT signature segment is affected because signature segment decoding accepts
  characters outside the canonical Base64URL representation. This occurs when
  non…
severity: medium
cvss: 4.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'
cwe:
  - CWE-180
vendor: jpadilla
product: pyjwt
affected:
  - pyjwt < 2.14.0
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T21:17:14.773'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102269'
references:
  - url: >-
      https://github.com/jpadilla/pyjwt/commit/e6f48401001609a8f99e71fcaf355fb895d508a8
    label: security-advisories@github.com
  - url: 'https://github.com/jpadilla/pyjwt/releases/tag/2.14.0'
    label: security-advisories@github.com
  - url: 'https://github.com/jpadilla/pyjwt/security/advisories/GHSA-hxm8-2xgr-2p9m'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T21:20:54.780Z'
---

## Overview

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT signature segment is affected because signature segment decoding accepts characters outside the canonical Base64URL representation. This occurs when non-Base64URL characters are appended to a valid compact JWS signature segment. As a result, base64url_decode produces the same signature bytes for different serialized segments. Consequently, raw-token revocation checks can fail to recognize an equivalent modified token. This issue is fixed in version 2.14.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
