CVE-2026-102275
Received Received - Intake

PyJWT OKPAlgorithm Private Key Misuse Vulnerability

Vulnerability report for CVE-2026-102275, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in jwt/algorithms.py is affected because private-JWK import path does not compare the public key derived from d with x. This occurs when an OKP private JWK supplies non-corresponding x and d components. As a result, identity derived from x can differ from operations performed with d. Consequently, if an integration also accepts private key parameters from a proof header without rejecting them, an attacker may use a stolen sender-constrained token without the legitimate private key. This issue is fixed in version 2.15.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
pyjwt pyjwt From 2.1.0 (inc) to 2.15.0 (inc)
pyjwt pyjwt 2.15.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
CWE-348 The product has two different sources of the same data or information, but it uses the source that has less support for verification, is less trusted, or is less resistant to attack.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

PyJWT versions 2.1.0 to 2.15.0 have a flaw in the OKPAlgorithm.from_jwk function where private JWK import does not verify if the public key derived from d matches the provided x component. This allows an attacker to manipulate identity checks if the integration accepts private key parameters from a proof header without proper validation.

Detection Guidance

This vulnerability affects PyJWT versions 2.1.0 to 2.15.0. To detect it, check the installed PyJWT version using 'pip show PyJWT' or 'pip list | grep PyJWT'. If the version is between 2.1.0 and 2.15.0, the system is vulnerable.

Impact Analysis

An attacker could exploit this to use a stolen token without the legitimate private key, potentially bypassing authentication or authorization mechanisms. This could lead to unauthorized access to sensitive data or actions if the system relies on JWT validation.

Compliance Impact

This vulnerability could compromise data integrity and access controls, potentially violating GDPR's security requirements or HIPAA's access safeguards. Non-compliance may result if unauthorized access occurs due to this flaw.

Mitigation Strategies

Upgrade PyJWT to version 2.15.0 or later immediately using 'pip install --upgrade PyJWT'. If upgrading is not possible, consider disabling OKPAlgorithm.from_jwk or restricting JWK imports to public keys only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102275. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart