---
id: CVE-2026-103001
title: PyJWT is a Python implementation of JSON Web Token standards
summary: >-
  PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0
  through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a
  caller-supplied mutable options mapping when verify_signature is false. If an
  application reuses…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N'
cwe:
  - CWE-471
vendor: jpadilla
product: pyjwt
affected:
  - 'pyjwt >= 2.11.0, <= 2.13.0'
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:16:33.537'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103001'
references:
  - url: >-
      https://github.com/jpadilla/pyjwt/commit/0c87c8c8b1a74cac99ad8115f3050efcb7fbed35
    label: security-advisories@github.com
  - url: 'https://github.com/jpadilla/pyjwt/issues/679'
    label: security-advisories@github.com
  - url: 'https://github.com/jpadilla/pyjwt/security/advisories/GHSA-gvp8-978c-rx2q'
    label: security-advisories@github.com
  - url: 'https://github.com/advisories/GHSA-gvp8-978c-rx2q'
tags:
  - nvd
  - cve.org
  - ghsa
  - pip
ingestedAt: '2026-09-30T22:27:27.820Z'
aliases:
  - GHSA-gvp8-978c-rx2q
ecosystem: pip
---

## Overview

PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses that same mapping for a later decode() or decode_complete() call and changes verify_signature to true, the mapping can retain false values for expiration, not-before, issued-at, audience, issuer, subject, and JWT ID checks. A signed token with invalid registered claims can then be accepted without disabling signature verification, but applications that create a fresh options mapping for each call are not affected.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-103001)

Affected packages:

- `PyJWT >= 2.11.0, <= 2.13.0`

Source: https://github.com/advisories/GHSA-gvp8-978c-rx2q
