CVE-2026-102269
Received Received - Intake

PyJWT Signature Segment Decoding Vulnerability Prior to 2.14.0

Vulnerability report for CVE-2026-102269, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT signature segment is affected because signature segment decoding accepts characters outside the canonical Base64URL representation. This occurs when non-Base64URL characters are appended to a valid compact JWS signature segment. As a result, base64url_decode produces the same signature bytes for different serialized segments. Consequently, raw-token revocation checks can fail to recognize an equivalent modified token. This issue is fixed in version 2.14.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pyjwt pyjwt 2.14.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-180 The product validates input before it is canonicalized, which prevents the product from detecting data that becomes invalid after the canonicalization step.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

PyJWT before 2.14.0 has a flaw where the signature segment decoding accepts non-Base64URL characters appended to a valid compact JWS signature. This causes base64url_decode to produce identical signature bytes for different token segments, allowing modified tokens to bypass raw-token revocation checks.

Detection Guidance

To detect this vulnerability, check the installed version of PyJWT using pip show PyJWT. If the version is below 2.14.0, the system is vulnerable. Update PyJWT to version 2.14.0 or later to mitigate the issue.

Impact Analysis

An attacker could craft a token with extra characters that appears different but produces the same signature. This might bypass revocation checks, allowing unauthorized access to systems relying on JWT token validation for authentication or session management.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations using PyJWT before 2.14.0 may fail compliance audits due to insufficient token validation controls.

Mitigation Strategies

Upgrade PyJWT to version 2.14.0 or later to address the signature segment decoding issue. Review tokens for non-Base64URL characters in signatures and implement strict validation of JWT signatures.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102269. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart