CVE-2026-102274
Received Received - Intake

Denial of Service in PyJWT JWKSet Handling

Vulnerability report for CVE-2026-102274, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

PyJWT is a Python implementation of JSON Web Token standards. From 2.9.0 until 2.14.0, PyJWKSet does not catch the plain ValueError raised for malformed RSA JWK components by RSAAlgorithm.from_jwk in jwt/api_jwk.py. This occurs when a JWK Set contains a malformed RSA key alongside otherwise usable keys. As a result, one malformed member aborts construction of the entire PyJWKSet. Consequently, applications can experience authentication failures or request-level denial of service. This issue is fixed in version 2.14.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
pyjwt pyjwt to 2.14.0 (inc)
pyjwt pyjwt 2.14.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-755 The product does not handle or incorrectly handles an exceptional condition.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

PyJWT versions 2.9.0 to 2.14.0 have a flaw in PyJWKSet where a malformed RSA JWK component raises a ValueError that is not caught. This causes the entire PyJWKSet construction to fail, leading to potential authentication failures or denial of service when processing requests.

Detection Guidance

To detect this vulnerability, check the installed version of PyJWT using pip show PyJWT. If the version is between 2.9.0 and 2.14.0, the system is vulnerable. Test for malformed RSA JWK components by attempting to load a JWK Set with a malformed key and observing if PyJWKSet fails to initialize.

Impact Analysis

This vulnerability can cause applications to fail authentication checks or become unavailable due to denial of service if a malformed RSA key is present in a JWK Set. It may disrupt services relying on JWT validation.

Compliance Impact

This vulnerability could indirectly impact compliance with GDPR or HIPAA by causing authentication failures or denial of service in applications handling sensitive data. If authentication is disrupted, it may lead to unauthorized access or service interruptions, violating data protection or availability requirements under these regulations.

Mitigation Strategies

Upgrade PyJWT to version 2.14.0 or later immediately. Use pip install --upgrade PyJWT to apply the fix. Review JWK Sets for malformed RSA keys to prevent authentication failures or denial of service.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102274. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart