CVE-2026-101917
Received Received - Intake

Denial of Service in PyJWT via JWKS Cache Refresh

Vulnerability report for CVE-2026-101917, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT get_signing_key_from_jwt is affected because unknown kid misses force refreshes without a negative cache or minimum refresh interval. This occurs when unauthenticated tokens repeatedly use the same unknown kid or varying kid values absent from the cached JWKS. As a result, each cache miss causes PyJWKClient to refresh the JWKS. Consequently, attacker traffic can amplify outbound requests to the configured JWKS endpoint. This issue is fixed in version 2.14.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
pyjwt pyjwt 2.14.0
pyjwt pyjwt to 2.14.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

PyJWT before 2.14.0 has a flaw in get_signing_key_from_jwt where an unknown kid value triggers repeated JWKS refreshes without proper caching controls. This leads to excessive outbound requests to the JWKS endpoint when unauthenticated tokens use unknown or varying kid values.

Detection Guidance

To detect this vulnerability, monitor outbound requests to JWKS endpoints from systems using PyJWT versions before 2.14.0. Check for repeated requests with unknown or varying kid values that trigger JWKS refreshes. Use network tools like tcpdump or Wireshark to capture and analyze traffic patterns.

Impact Analysis

An attacker could exploit this by sending many tokens with unknown kid values, causing your server to repeatedly fetch JWKS data. This may result in increased server load, potential denial of service, or network congestion due to amplified outbound traffic.

Compliance Impact

This vulnerability may impact compliance by increasing server resource usage and exposing systems to denial of service risks. GDPR and HIPAA require safeguarding data integrity and availability; excessive server load could hinder compliance with these requirements.

Mitigation Strategies

Upgrade PyJWT to version 2.14.0 or later to address the vulnerability. Monitor network traffic for unusual outbound requests to JWKS endpoints that may indicate exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101917. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart