jpadilla has 13 CVEs on record. Disclosure cadence is accelerating: 13 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 13. The median CVSS is 6.5 (medium), with 1 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-347 (5).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 13 prev 0
Weakness classes
Products
- pyjwt 13
Worst active — by depth score
CVE-2026-102268Critical· 9.1PyJWT is a Python implementation of JSON Web Token standards50CVE-2026-102273High· 7.4PyJWT is a Python implementation of JSON Web Token standards41CVE-2026-102272High· 7.4PyJWT is a Python implementation of JSON Web Token standards41CVE-2026-102271High· 7.4PyJWT is a Python implementation of JSON Web Token standards41CVE-2026-102267High· 7.4PyJWT is a Python implementation of JSON Web Token standards41
jpadilla vulnerabilities
CVEs affecting jpadilla, newest first. Open any entry for full detail, references, and exploit status.
13 CVEsRSS
CVE-2026-102275Medium· 6.5PyJWT is a Python implementation of JSON Web Token standards
PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in jwt/algorithms.py is affected because private-JWK import path does not compare the public key derived from d with x. T…
CVE-2026-102274Medium· 5.9PyJWT is a Python implementation of JSON Web Token standards
PyJWT is a Python implementation of JSON Web Token standards. From 2.9.0 until 2.14.0, PyJWKSet does not catch the plain ValueError raised for malformed RSA JWK components by RSAAlgorithm.from_jwk in jwt/api_jwk.py. This occurs when a J…
CVE-2026-102273High· 7.4PyJWT is a Python implementation of JSON Web Token standards
PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because HMAC key guard only recognizes top-level public JWK forms and misses container representations. T…
CVE-2026-102272High· 7.4PyJWT is a Python implementation of JSON Web Token standards
PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.prepare_key in jwt/algorithms.py is affected because raw-JWK detector does not normalize accepted Unicode byte-order marks before check…
CVE-2026-102271High· 7.4PyJWT is a Python implementation of JSON Web Token standards
PyJWT is a Python implementation of JSON Web Token standards. From 2.4.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because asymmetric-key guard relies on textual markers that are absent from DER encoding. This occurs when…
CVE-2026-102270Medium· 4.4PyJWT is a Python implementation of JSON Web Token standards
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT is_pem_format is affected because lazy PEM regular expression backtracks extensively. This occurs when a certificate-like input contains repeated BEGIN …
CVE-2026-102269Medium· 4.8PyJWT is a Python implementation of JSON Web Token standards
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT signature segment is affected because signature segment decoding accepts characters outside the canonical Base64URL representation. This occurs when non…
CVE-2026-102268Critical· 9.1PyJWT is a Python implementation of JSON Web Token standards
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected because is_pem_format does not recognize every PEM representation accepted by the cryptography loader. This occurs w…
CVE-2026-102267High· 7.4PyJWT is a Python implementation of JSON Web Token standards
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT PyJWKClient is affected because redirect destinations are not revalidated against the JWKS trust boundary. This occurs when a configured trusted JWKS en…
CVE-2026-102266High· 7.4PyJWT is a Python implementation of JSON Web Token standards
PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.from_jwk is affected because PyJWK verification path used the decoded key without applying prepare_key validation. This occurs when a t…
CVE-2026-102265Medium· 5.3PyJWT is a Python implementation of JSON Web Token standards
PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWS._load in jwt/api_jws.py is affected because parser catches ValueError but not RecursionError. This occurs when a deeply nested token header rea…
CVE-2026-101918Medium· 5.3PyJWT is a Python implementation of JSON Web Token standards
PyJWT is a Python implementation of JSON Web Token standards. From 2.0.0a1 until 2.15.0, PyJWT PyJWKClient.get_signing_key_from_jwt is affected because payload parser catches ValueError but not RecursionError. This occurs when an attacke…
CVE-2026-101917Medium· 5.3PoCPyJWT is a Python implementation of JSON Web Token standards
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT get_signing_key_from_jwt is affected because unknown kid misses force refreshes without a negative cache or minimum refresh interval. This occurs when u…