CVE-2026-102269

medium

Description

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT signature segment is affected because signature segment decoding accepts characters outside the canonical Base64URL representation. This occurs when non-Base64URL characters are appended to a valid compact JWS signature segment. As a result, base64url_decode produces the same signature bytes for different serialized segments. Consequently, raw-token revocation checks can fail to recognize an equivalent modified token. This issue is fixed in version 2.14.0.

References

https://github.com/jpadilla/pyjwt/security/advisories/GHSA-hxm8-2xgr-2p9m

https://github.com/jpadilla/pyjwt/releases/tag/2.14.0

https://github.com/jpadilla/pyjwt/commit/e6f48401001609a8f99e71fcaf355fb895d508a8

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-88536

Details

Source: Mitre, NVD

Published: 2026-09-28

Updated: 2026-09-30

Named Vulnerability: GHSA-hxm8-2xgr-2p9m

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 4.8

Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00198