AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-101917.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 29, 2026

Disclosure summary

Summary CVE-2026-48524 (GHSA-fhv5-28vv-h8m8, "PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)") was fixed in 2.13.0 by stopping fetch_data() from clearing the cache on a fetch error. That closed one amplification path but did not add the mitigation the advisory's title implies: there is still no rate-limit, negative-cache, or minimum-refresh-interval for unknown kids. At HEAD, get_signing_key(kid) (jwt/jwks_client.py:185-211), on any unknown kid, calls get_signing_keys(refresh=True), and refresh=True bypasses jwk_set_cache unconditionally and forces a fresh fetch_data(). The kid is read from the unverified token header (get_signing_key_from_jwt decodes with verify_signature=False), so no valid token and no authentication is required. lru_cache does not cache the raised exception, so even the same unknown kid repeated re-fetches on every call. Affected pyjwt fetches: 9 same unknown kid x5 -> extra fetches: 5 Each unknown kid forces a fresh JWKS fetch; a repeated identical unknown kid still re-fetches every time against an unexpired cache. No rate-limit or negative-cache. Impact One unauthenticated request -> one outbound JWKS HTTP fetch + full J

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-2gx3-rcp4-g85q

Open original source · Updated Sep 29, 2026

PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
pippyjwt2.14.0

Original records & references

PUBLISHED 2026-09-29T19:11:51-04:00
MODIFIED 2026-09-29T19:11:54-04:00
INGESTED 2026-10-06T11:43:08-04:00