CVE-2026-102268
Received Received - Intake

PyJWT HMAC Forgery via PEM Misinterpretation

Vulnerability report for CVE-2026-102268, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected because is_pem_format does not recognize every PEM representation accepted by the cryptography loader. This occurs when an application mixes HMAC and asymmetric algorithms and supplies a mutated public-key PEM as raw key bytes. As a result, HMACAlgorithm.prepare_key treats the unrecognized asymmetric public key as an HMAC secret. Consequently, an attacker who knows the public key can forge authenticated HMAC tokens. This issue is fixed in version 2.14.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pyjwt pyjwt to 2.14.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

PyJWT before 2.14.0 has a flaw in jwt/utils.py where is_pem_format fails to recognize all valid PEM formats accepted by the cryptography loader. When HMAC and asymmetric algorithms are mixed and a mutated public-key PEM is provided as raw bytes, HMACAlgorithm.prepare_key incorrectly treats the asymmetric public key as an HMAC secret. This allows an attacker with knowledge of the public key to forge authenticated HMAC tokens.

Detection Guidance

Check PyJWT version with pip show PyJWT. If version is below 2.14.0, the system is vulnerable. Review code for mixed HMAC and asymmetric algorithm usage with public-key PEM inputs.

Impact Analysis

If you use PyJWT versions before 2.14.0 with mixed HMAC and asymmetric algorithms, an attacker could forge tokens to gain unauthorized access or impersonate users. This could lead to data breaches, privilege escalation, or other security incidents depending on the application's use of JWTs.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating GDPR's integrity and confidentiality principles or HIPAA's safeguards for protected health information. Non-compliance may result in legal penalties, fines, or reputational damage.

Mitigation Strategies

Upgrade PyJWT to version 2.14.0 or later. Audit applications using PyJWT to ensure proper key handling and avoid mixing HMAC with asymmetric algorithms.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102268. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart