CVE-2026-102270Medium· 4.4▾ SunlitPyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT is_pem_format is affected because lazy PEM regular expression backtracks extensively. This occurs when a certificate-like input contains repeated BEGIN …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 24.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT is_pem_format is affected because lazy PEM regular expression backtracks extensively. This occurs when a certificate-like input contains repeated BEGIN markers without a matching END marker. As a result, is_pem_format performs unbounded backtracking while searching for a PEM end marker. Consequently, an attacker can cause intensive CPU consumption. This issue is fixed in version 2.14.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102268Critical· 9.1PyJWT is a Python implementation of JSON Web Token standards
CVE-2026-102273High· 7.4PyJWT is a Python implementation of JSON Web Token standards
CVE-2026-102274Medium· 5.9PyJWT is a Python implementation of JSON Web Token standards
CVE-2026-102271High· 7.4PyJWT is a Python implementation of JSON Web Token standards
CVE-2026-102272High· 7.4PyJWT is a Python implementation of JSON Web Token standards
CVE-2026-102267High· 7.4PyJWT is a Python implementation of JSON Web Token standards