AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-102267.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 29, 2026

Disclosure summary

### Summary PyJWT 2.13.0 `PyJWKClient` followed HTTP redirects while fetching a JWKS, without validating the redirect destination. A configured trusted endpoint could therefore redirect the client to a different host. ### Impact When an application uses `PyJWKClient` with caller-supplied request headers and an attacker can influence the configured endpoint's response, the redirected request could expose those headers and the redirected response could be used as authoritative key material. This could cause JWKS trust poisoning and, in affected mixed-configuration applications, forged JWT acceptance. The issue requires an attacker-influenced redirect from the configured JWKS endpoint; it is not triggered by a token `kid` alone. ### Affected versions PyJWT `

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-9v7f-9g4p-ffgj

Open original source · Updated Sep 29, 2026

PyJWT: PyJWKClient follows redirects when fetching JWKS

Source severity: HIGH / 0

EcosystemPackageAffected rangeFirst patched
pipPyJWT2.14.0

Original records & references

PUBLISHED 2026-09-29T19:15:00-04:00
MODIFIED 2026-09-29T19:15:00-04:00
INGESTED 2026-10-06T11:43:08-04:00