Skip to main content

Vendor archive

pyjwt_project CVEs

Beta · best-effort

10 CVEs tagged to vendor pyjwt_project0 Critical, 5 High, 3 Medium, 2 Low, 0 Unrated.

CVE-2026-48526

Published May 28, 2026

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the libra…

CVSS 7.4 · High
evidence mentions
31
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2026-48525

Published May 28, 2026

PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option ("b64": false, RFC 7797), PyJWT per…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48524

Published May 28, 2026

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown k…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48523

Published May 28, 2026

PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are calle…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-48522

Published May 28, 2026

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default Op…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-32597

Published Mar 13, 2026

PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token con…

CVSS 7.5 · High
evidence mentions
35
Buzz score
44.5
Vendor/product tagsBeta · best-effort

CVE-2025-45768

Published Jul 31, 2025

pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admitted…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53861

Published Nov 29, 2024

pyjwt is a JSON Web Token implementation in Python. An incorrect string comparison is run for `iss` checking, resulting in `"acb"` being accepted for `"_abc_"`. This is a bug intr…

CVSS 2.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-29217

Published May 24, 2022

PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT token can choose the used signing…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11424

Published Aug 24, 2017

In PyJWT 1.5.0 and below the `invalid_strings` check in `HMACAlgorithm.prepare_key` does not account for all PEM encoded public keys. Specifically, the PKCS1 PEM encoded format wo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1