PyJWT is affected by two denial-of-service vulnerabilities involving crafted attacker-controlled input. CVE-2026-102270 affects versions below 2.14.0 and involves inefficient regex processing in is_pem_format, which can cause excessive CPU consumption. It has a CVSS score of 4.4 (Medium). CVE-2026-101918 affects versions 2.0.0a1 to below 2.15.0 and can trigger an uncaught RecursionError when deeply nested JWT payloads are parsed before signature verification. It has a CVSS score of 5.3 (Medium). Both vulnerabilities can be exploited with malicious input to affect application availability.
CVE-2026-102270: PyJWT versions below 2.14.0 are affected by inefficient regex processing in is_pem_format. Crafted certificate-like input can trigger excessive backtracking and CPU consumption, potentially causing denial of service. The vulnerability has a CVSS score of 4.4 (Medium).[/subscribe_to_unlock_form]
PyJWT is affected by two denial-of-service vulnerabilities involving crafted attacker-controlled input. CVE-2026-102270 affects versions below 2.14.0 and involves inefficient regex processing in is_pem_format, which can cause excessive CPU consumption. It has a CVSS score of 4.4 (Medium). CVE-2026-101918 affects versions 2.0.0a1 to below 2.15.0 and can trigger an uncaught RecursionError when deeply nested JWT payloads are parsed before signature verification. It has a CVSS score of 5.3 (Medium). Both vulnerabilities can be exploited with malicious input to affect application availability.
CVE-2026-102270: PyJWT versions below 2.14.0 are affected by inefficient regex processing in is_pem_format. Crafted certificate-like input can trigger excessive backtracking and CPU consumption, potentially causing denial of service. The vulnerability has a CVSS score of 4.4 (Medium).[emaillocker id="1283"]
CVE-2026-101918: PyJWT versions 2.0.0a1 to below 2.15.0 are affected by improper handling of deeply nested JWT payloads. Malicious input can trigger an uncaught RecursionError during pre-verification parsing, potentially causing application errors and denial of service. The vulnerability has a CVSS score of 5.3 (Medium).
Both vulnerabilities can impact the availability of applications processing attacker-controlled PyJWT input and should be addressed in affected deployments.
We recommend you to update PyJWT to version 2.15.0.
The following reports contain further technical details:
[/emaillocker]