---
id: CVE-2026-32597
title: PyJWT is a JSON Web Token implementation in Python
summary: >-
  PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT
  does not validate the crit (Critical) Header Parameter defined in RFC 7515
  §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT
  does not …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-345
  - CWE-863
  - CWE-347
vendor: pyjwt_project
product: pyjwt
affected:
  - pyjwt < 2.12.0
patched:
  - pyjwt 2.12.0
published: '2026-03-13'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T13:18:12.027'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-32597'
references:
  - url: 'https://github.com/jpadilla/pyjwt/security/advisories/GHSA-752w-5fwx-jx9f'
    label: security-advisories@github.com
  - url: 'https://lists.debian.org/debian-lts-announce/2026/05/msg00008.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2026:10140'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:10141'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:10184'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:12176'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13508'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13512'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13545'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13553'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13672'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:13916'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:17083'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19138'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19355'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19375'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:19712'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:21431'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:21517'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:22330'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:24977'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:26226'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:37275'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:42644'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:6568'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:6720'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:6912'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:6926'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8437'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8746'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8747'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:8748'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-32597'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2447194'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://github.com/jpadilla/pyjwt/security/advisories/GHSA-752w-5fwx-jx9f'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32597.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-32597'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-32597'
  - url: 'https://github.com/jpadilla/pyjwt'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/pyjwt/PYSEC-2026-120.yaml
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
  - osv
  - pip
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-03-13T14:48:42.534762Z'
epss: 0.00269
epssPercentile: 0.19275
ingestedAt: '2026-07-01T15:50:58.690Z'
aliases:
  - GHSA-752w-5fwx-jx9f
  - PYSEC-2026-120
ecosystem: pip
---

## Overview

PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.

## Affected

- `pyjwt < 2.12.0`

## Remediation

Upgrade past the affected range:

- `pyjwt 2.12.0`

## Vendor advisories

- **RHSA-2026:13512** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-05-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:13512)
- **RHSA-2026:13508** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-05-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:13508)
- **RHSA-2026:17083** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-05-13 · [advisory](https://access.redhat.com/errata/RHSA-2026:17083)
- **RHSA-2026:13916** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-05-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:13916)
- **RHSA-2026:19138** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-05-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:19138)
- **RHSA-2026:12176** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8), Red Hat Enterprise Linux HighAvailability (v. 8), Red Hat Enterprise Linux ResilientStorage (v. 8) · released 2026-04-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:12176)
- **RHSA-2026:22330** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2), Red Hat Enterprise Linux High Availability E4S (v.9.2), Red Hat Enterprise Linux Resilient Storage E4S (v.9.2) · released 2026-06-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:22330)
- **RHSA-2026:21517** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.4), Red Hat Enterprise Linux High Availability EUS (v.9.4), Red Hat Enterprise Linux Resilient Storage EUS (v.9.4) · released 2026-05-28 · [advisory](https://access.redhat.com/errata/RHSA-2026:21517)
- **RHSA-2026:21431** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-05-27 · [advisory](https://access.redhat.com/errata/RHSA-2026:21431)
- **RHSA-2026:13672** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-05-05 · [advisory](https://access.redhat.com/errata/RHSA-2026:13672)
- **RHSA-2026:19355** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-05-19 · [advisory](https://access.redhat.com/errata/RHSA-2026:19355)
- **Red Hat VEX** · Important · affected: OpenShift Lightspeed, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat OpenShift AI (RHOAI), Red Hat Satellite 6, Red Hat Trusted Artifact Signer · no fix planned: OpenShift Lightspeed, Red Hat Ansible Automation Platform 2, Red Hat AI Inference Server, Red Hat OpenShift AI (RHOAI), … · updated 2026-09-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32597.json)

## Package advisory (CVE-2026-32597)

Affected packages:

- `pyjwt < 2.12.0`

Patched in:

- `pyjwt 2.12.0`

Source: https://osv.dev/vulnerability/GHSA-752w-5fwx-jx9f
