CVE-2026-102273
Received Received - Intake

HMAC Key Guard Bypass in PyJWT

Vulnerability report for CVE-2026-102273, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because HMAC key guard only recognizes top-level public JWK forms and misses container representations. This occurs when an application allows HMAC and asymmetric algorithms and passes a public JWK container as the raw key. As a result, public asymmetric key material is accepted as the HMAC secret. Consequently, an attacker who knows the public key can forge a token with arbitrary authenticated claims. This issue is fixed in version 2.14.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pyjwt pyjwt From 2.13.0 (inc) to 2.14.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

PyJWT versions 2.13.0 to 2.14.0 have a flaw in HMACAlgorithm.prepare_key where it only checks top-level public JWK forms and misses container representations. This allows public asymmetric key material to be accepted as an HMAC secret, enabling attackers with knowledge of the public key to forge tokens with arbitrary authenticated claims.

Detection Guidance

Check PyJWT version with pip show PyJWT. If version is between 2.13.0 and 2.14.0, the system is vulnerable. Review code for HMAC key handling and JWK container usage.

Impact Analysis

If you use PyJWT versions 2.13.0 to 2.14.0 and allow both HMAC and asymmetric algorithms, an attacker could forge tokens with fake claims, potentially gaining unauthorized access to systems or data protected by JWT authentication.

Compliance Impact

This vulnerability could lead to unauthorized access or data breaches, violating confidentiality and integrity requirements in GDPR and HIPAA. Non-compliance may result in legal penalties or reputational damage.

Mitigation Strategies

Upgrade PyJWT to version 2.14.0 or later. If immediate upgrade is not possible, avoid using public JWK containers as HMAC keys and restrict algorithm usage to symmetric keys only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102273. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart