---
id: CVE-2026-48526
title: PyJWT is a JSON Web Token implementation in Python
summary: >-
  PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the
  verifier is decoding JSON Web Tokens, while supporting both asymmetric and
  HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC
  algorith…
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-287
  - CWE-347
vendor: pyjwt_project
product: pyjwt
affected:
  - pyjwt < 2.13.0
patched:
  - pyjwt 2.13.0
published: '2026-05-28'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T13:20:19.447'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-48526'
references:
  - url: 'https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx'
    label: security-advisories@github.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:25902'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:25928'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:26206'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:28571'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:30076'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:30088'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:30089'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:33683'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:34160'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:34365'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:34374'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:35835'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:35836'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:35837'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:35845'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:36350'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:37275'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:40967'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:41066'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:42132'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:42142'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:42144'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:42644'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:42796'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:43038'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:48085'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:50222'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:50223'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:50263'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:50319'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:50336'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:50340'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:50904'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60520'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-48526'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2482734'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48526.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-48526'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-48526'
  - url: 'https://github.com/jpadilla/pyjwt'
  - url: >-
      https://github.com/pypa/advisory-database/tree/main/vulns/pyjwt/PYSEC-2026-179.yaml
  - url: 'https://access.redhat.com/errata/RHSA-2026:69466'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69467'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69469'
  - url: 'https://access.redhat.com/errata/RHSA-2026:69464'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70965'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70979'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70995'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70969'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
  - osv
  - pip
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-05-29T03:55:56.833915Z'
epss: 0.00427
epssPercentile: 0.34197
ingestedAt: '2026-07-02T15:38:24.975Z'
aliases:
  - GHSA-xgmm-8j9v-c9wx
  - PYSEC-2026-179
ecosystem: pip
---

## Overview

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret key for HMAC algorithm. This vulnerability is fixed in 2.13.0.

## Affected

- `pyjwt < 2.13.0`

## Remediation

Upgrade past the affected range:

- `pyjwt 2.13.0`

## Vendor advisories

- **RHSA-2026:50319** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50319)
- **RHSA-2026:50223** · Red Hat · fixed in: Red Hat Satellite 6.16 for RHEL 8, Red Hat Satellite 6.16 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50223)
- **RHSA-2026:50336** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50336)
- **RHSA-2026:34160** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-07-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:34160)
- **RHSA-2026:50222** · Red Hat · fixed in: Red Hat Satellite 6.17 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50222)
- **RHSA-2026:50263** · Red Hat · fixed in: Red Hat Satellite 6.18 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50263)
- **RHSA-2026:34365** · Red Hat · fixed in: Red Hat Satellite 6.19 for RHEL 9 · released 2026-07-01 · [advisory](https://access.redhat.com/errata/RHSA-2026:34365)
- **RHSA-2026:35845** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-07-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:35845)
- **RHSA-2026:25902** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-06-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:25902)
- **RHSA-2026:35837** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2), Red Hat Enterprise Linux High Availability E4S (v.9.2), Red Hat Enterprise Linux Resilient Storage E4S (v.9.2) · released 2026-07-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:35837)
- **RHSA-2026:35836** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4), Red Hat Enterprise Linux High Availability E4S (v.9.4), Red Hat Enterprise Linux Resilient Storage E4S (v.9.4) · released 2026-07-06 · [advisory](https://access.redhat.com/errata/RHSA-2026:35836)
- **Red Hat VEX** · Important · affected: OpenShift Lightspeed, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · no fix planned: Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, OpenShift Lightspeed, Red Hat Enterprise Linux AI (RHEL AI) 3, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48526.json)

## Package advisory (CVE-2026-48526)

Affected packages:

- `pyjwt < 2.13.0`

Patched in:

- `pyjwt 2.13.0`

Source: https://osv.dev/vulnerability/GHSA-xgmm-8j9v-c9wx
