CVE-2026-102271
Received Received - Intake

HMAC Forgery in PyJWT Due to DER Public Key Handling

Vulnerability report for CVE-2026-102271, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

PyJWT is a Python implementation of JSON Web Token standards. From 2.4.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because asymmetric-key guard relies on textual markers that are absent from DER encoding. This occurs when an application mixes HMAC and asymmetric algorithms and supplies a DER public key as the shared verification key. As a result, PyJWT uses public DER bytes as an HMAC secret. Consequently, an attacker who knows the public key can forge authenticated HMAC tokens. This issue is fixed in version 2.14.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pyjwt pyjwt From 2.4.0 (inc) to 2.14.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

PyJWT versions 2.4.0 to 2.14.0 have a flaw in HMACAlgorithm.prepare_key where asymmetric-key checks fail for DER-encoded public keys. This allows attackers to misuse public keys as HMAC secrets, enabling token forgery if HMAC and asymmetric algorithms are mixed in the application.

Detection Guidance

To detect this vulnerability, check if your PyJWT version is between 2.4.0 and 2.14.0. Run: pip show PyJWT. If the version is in this range, the system is vulnerable. Additionally, review code for mixed HMAC and asymmetric algorithm usage with DER public keys.

Impact Analysis

If your application uses PyJWT with mixed HMAC and asymmetric algorithms and accepts DER-encoded public keys, an attacker who knows the public key could forge valid HMAC tokens. This could lead to unauthorized access or data manipulation in the affected system.

Compliance Impact

This vulnerability could lead to unauthorized token forgery, potentially compromising authentication mechanisms. For GDPR, this may impact data integrity and security measures required under Articles 32 and 5. For HIPAA, it could affect access controls and integrity of protected health information as outlined in the Security Rule.

Mitigation Strategies

Upgrade PyJWT to version 2.14.0 or later to address the issue. Review applications using PyJWT to ensure they do not mix HMAC and asymmetric algorithms with DER public keys as shared verification keys.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102271. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart