VulnSea

jpadilla has 13 CVEs on record. Disclosure cadence is accelerating: 13 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 13. The median CVSS is 6.5 (medium), with 1 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-347 (5).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
—
Last 90 days
13 prev 0

Products

  • pyjwt 13
13
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

jpadilla vulnerabilities

CVEs affecting jpadilla, newest first. Open any entry for full detail, references, and exploit status.

13 CVEsRSS

CVE-2026-102275Medium· 6.5
today

PyJWT is a Python implementation of JSON Web Token standards

PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in jwt/algorithms.py is affected because private-JWK import path does not compare the public key derived from d with x. T…

▾ Sunlitjpadilla · pyjwtvia NVD
CVE-2026-102274Medium· 5.9
today

PyJWT is a Python implementation of JSON Web Token standards

PyJWT is a Python implementation of JSON Web Token standards. From 2.9.0 until 2.14.0, PyJWKSet does not catch the plain ValueError raised for malformed RSA JWK components by RSAAlgorithm.from_jwk in jwt/api_jwk.py. This occurs when a J…

▾ Sunlitjpadilla · pyjwtvia NVD
CVE-2026-102273High· 7.4
today

PyJWT is a Python implementation of JSON Web Token standards

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because HMAC key guard only recognizes top-level public JWK forms and misses container representations. T…

▾ Twilightjpadilla · pyjwtvia NVD
CVE-2026-102272High· 7.4
today

PyJWT is a Python implementation of JSON Web Token standards

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.prepare_key in jwt/algorithms.py is affected because raw-JWK detector does not normalize accepted Unicode byte-order marks before check…

▾ Twilightjpadilla · pyjwtvia NVD
CVE-2026-102271High· 7.4
today

PyJWT is a Python implementation of JSON Web Token standards

PyJWT is a Python implementation of JSON Web Token standards. From 2.4.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because asymmetric-key guard relies on textual markers that are absent from DER encoding. This occurs when…

▾ Twilightjpadilla · pyjwtvia NVD
CVE-2026-102270Medium· 4.4
today

PyJWT is a Python implementation of JSON Web Token standards

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT is_pem_format is affected because lazy PEM regular expression backtracks extensively. This occurs when a certificate-like input contains repeated BEGIN …

▾ Sunlitjpadilla · pyjwtvia NVD
CVE-2026-102269Medium· 4.8
today

PyJWT is a Python implementation of JSON Web Token standards

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT signature segment is affected because signature segment decoding accepts characters outside the canonical Base64URL representation. This occurs when non…

▾ Sunlitjpadilla · pyjwtvia NVD
CVE-2026-102268Critical· 9.1
today

PyJWT is a Python implementation of JSON Web Token standards

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected because is_pem_format does not recognize every PEM representation accepted by the cryptography loader. This occurs w…

▾ Midnightjpadilla · pyjwtvia NVD
CVE-2026-102267High· 7.4
today

PyJWT is a Python implementation of JSON Web Token standards

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT PyJWKClient is affected because redirect destinations are not revalidated against the JWKS trust boundary. This occurs when a configured trusted JWKS en…

▾ Twilightjpadilla · pyjwtvia NVD
CVE-2026-102266High· 7.4
today

PyJWT is a Python implementation of JSON Web Token standards

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.from_jwk is affected because PyJWK verification path used the decoded key without applying prepare_key validation. This occurs when a t…

▾ Twilightjpadilla · pyjwtvia NVD
CVE-2026-102265Medium· 5.3
today

PyJWT is a Python implementation of JSON Web Token standards

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWS._load in jwt/api_jws.py is affected because parser catches ValueError but not RecursionError. This occurs when a deeply nested token header rea…

▾ Sunlitjpadilla · pyjwtvia NVD
CVE-2026-101918Medium· 5.3
today

PyJWT is a Python implementation of JSON Web Token standards

PyJWT is a Python implementation of JSON Web Token standards. From 2.0.0a1 until 2.15.0, PyJWT PyJWKClient.get_signing_key_from_jwt is affected because payload parser catches ValueError but not RecursionError. This occurs when an attacke…

▾ Sunlitjpadilla · pyjwtvia NVD
CVE-2026-101917Medium· 5.3PoC
today

PyJWT is a Python implementation of JSON Web Token standards

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT get_signing_key_from_jwt is affected because unknown kid misses force refreshes without a negative cache or minimum refresh interval. This occurs when u…

▾ Twilightjpadilla · pyjwtvia NVD
jpadilla vulnerabilities (CVEs) · VulnSea