Threat Advisory

PyJWT Flaw Lets Attackers Trigger Denial-of-Service

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

PyJWT is affected by two denial-of-service vulnerabilities involving crafted attacker-controlled input. CVE-2026-102270 affects versions below 2.14.0 and involves inefficient regex processing in is_pem_format, which can cause excessive CPU consumption. It has a CVSS score of 4.4 (Medium). CVE-2026-101918 affects versions 2.0.0a1 to below 2.15.0 and can trigger an uncaught RecursionError when deeply nested JWT payloads are parsed before signature verification. It has a CVSS score of 5.3 (Medium). Both vulnerabilities can be exploited with malicious input to affect application availability.

CVE-2026-102270: PyJWT versions below 2.14.0 are affected by inefficient regex processing in is_pem_format. Crafted certificate-like input can trigger excessive backtracking and CPU consumption, potentially causing denial of service. The vulnerability has a CVSS score of 4.4 (Medium).[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

PyJWT is affected by two denial-of-service vulnerabilities involving crafted attacker-controlled input. CVE-2026-102270 affects versions below 2.14.0 and involves inefficient regex processing in is_pem_format, which can cause excessive CPU consumption. It has a CVSS score of 4.4 (Medium). CVE-2026-101918 affects versions 2.0.0a1 to below 2.15.0 and can trigger an uncaught RecursionError when deeply nested JWT payloads are parsed before signature verification. It has a CVSS score of 5.3 (Medium). Both vulnerabilities can be exploited with malicious input to affect application availability.

CVE-2026-102270: PyJWT versions below 2.14.0 are affected by inefficient regex processing in is_pem_format. Crafted certificate-like input can trigger excessive backtracking and CPU consumption, potentially causing denial of service. The vulnerability has a CVSS score of 4.4 (Medium).[emaillocker id="1283"]

CVE-2026-101918: PyJWT versions 2.0.0a1 to below 2.15.0 are affected by improper handling of deeply nested JWT payloads. Malicious input can trigger an uncaught RecursionError during pre-verification parsing, potentially causing application errors and denial of service. The vulnerability has a CVSS score of 5.3 (Medium).

Both vulnerabilities can impact the availability of applications processing attacker-controlled PyJWT input and should be addressed in affected deployments.

RECOMMENDATION:

We recommend you to update PyJWT to version 2.15.0.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu