CVE-2026-102272High· 7.4▾ TwilightPyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.prepare_key in jwt/algorithms.py is affected because raw-JWK detector does not normalize accepted Unicode byte-order marks before check…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.prepare_key in jwt/algorithms.py is affected because raw-JWK detector does not normalize accepted Unicode byte-order marks before checking for JSON. This occurs when a public JWK is prefixed with a UTF-8 BOM and used in a mixed-algorithm verification path. As a result, public JWK bypasses asymmetric-key detection and becomes the HMAC secret. Consequently, an attacker who knows the public key can forge authenticated tokens. This issue is fixed in version 2.14.0.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-102273High· 7.4PyJWT is a Python implementation of JSON Web Token standards
CVE-2026-102271High· 7.4PyJWT is a Python implementation of JSON Web Token standards
CVE-2026-102268Critical· 9.1PyJWT is a Python implementation of JSON Web Token standards
CVE-2026-102266High· 7.4PyJWT is a Python implementation of JSON Web Token standards
CVE-2026-102274Medium· 5.9PyJWT is a Python implementation of JSON Web Token standards
CVE-2026-102270Medium· 4.4PyJWT is a Python implementation of JSON Web Token standards