VulnSea

pyjwt vulnerabilities

CVEs whose affected-version data names the pyjwt package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

7 CVEsRSS

CVE-2026-48524Low· 3.7
3mo ago

PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)

PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)

Sunlitpyjwt · pyjwtEPSS 0.36%via OSV
CVE-2026-48522Medium· 4.2
3mo ago

PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes

PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes

Sunlitpyjwt · pyjwtEPSS 0.22%via OSV
CVE-2026-48525Medium· 5.3
3mo ago

PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS

PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS

Sunlitpyjwt · pyjwtEPSS 0.37%via OSV
CVE-2026-48523Medium· 5.4
3mo ago

PyJWT is a JSON Web Token implementation in Python

PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. The token header alg is checked agains…

Sunlitpyjwt_project · pyjwtEPSS 0.13%via NVD
CVE-2026-48526High· 7.4PoC
3mo ago

PyJWT is a JSON Web Token implementation in Python

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorith…

Midnightpyjwt_project · pyjwtEPSS 0.40%via NVD
CVE-2026-32597High· 7.5PoC
6mo ago

PyJWT is a JSON Web Token implementation in Python

PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not …

Midnightpyjwt_project · pyjwtEPSS 0.27%via NVD
CVE-2024-53861Low· 2.2
1y ago

PyJWT Issuer field partial matches allowed

PyJWT Issuer field partial matches allowed

Sunlitpyjwt · pyjwtEPSS 0.83%via OSV
pyjwt vulnerabilities (CVEs) · VulnSea