pyjwt has 4 CVEs on record between 2024 and 2026. The busiest recent month was June 2026 with 3. The median CVSS is 4.0 (low).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 4.0
- Publish → KEV
- —
- Last 90 days
- 0 prev 3
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
CVE-2026-48525Medium· 5.3PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS29CVE-2026-48522Medium· 4.2PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes23CVE-2026-48524Low· 3.7PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)20CVE-2024-53861Low· 2.2PyJWT Issuer field partial matches allowed12
pyjwt vulnerabilities
CVEs affecting pyjwt, newest first. Open any entry for full detail, references, and exploit status.
4 CVEsRSS
CVE-2026-48524Low· 3.7PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
▾ Sunlitpyjwt · pyjwtEPSS 0.36%via OSV
CVE-2026-48522Medium· 4.2PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
▾ Sunlitpyjwt · pyjwtEPSS 0.22%via OSV
CVE-2026-48525Medium· 5.3PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS
PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS
▾ Sunlitpyjwt · pyjwtEPSS 0.37%via OSV
CVE-2024-53861Low· 2.2PyJWT Issuer field partial matches allowed
PyJWT Issuer field partial matches allowed
▾ Sunlitpyjwt · pyjwtEPSS 0.83%via OSV