AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-102272.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 29, 2026

Disclosure summary

## Affected Package - **Package**: PyJWT (`pyjwt` on PyPI) - **Repository**: https://www.google.com/url?q=https://github.com/jpadilla/pyjwt&source=gmail&ust=1781794518474000&sa=E - **Affected version**: 2.13.0 - **Vulnerability class**: Algorithm confusion / patch bypass --- ## Root Cause PyJWT 2.13.0 introduced a guard in `HMACAlgorithm.prepare_key()` (file `jwt/algorithms.py`, approximately line 344) to prevent RSA public key material from being used as an HMAC secret — the root cause of CVE-2026-48526. The guard uses `bytes.lstrip()` before calling `startswith(b"{")`: ```python stripped = key_bytes.lstrip() # strips ASCII whitespace only if stripped.startswith(b"{"): # JWK detection ... raise InvalidKeyError("The specified key is an asymmetric key...") ``` `bytes.lstrip()` with no argument removes only bytes in the ASCII whitespace set (`\x20 \t \n \r \x0b \x0c`). A UTF-8 BOM prefix (`\xef\xbb\xbf`) is not stripped, so `stripped.startswith(b"{")` returns `False` for any BOM-prefixed JWK JSON. The JWK detection block is never entered, and the RSA public key bytes are silently accepted as the HMAC-SHA256 secret. --- ## PoC Sketch (pseudocode — not a weaponized payload) ```python #

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-r6x4-923q-g947

Open original source · Updated Sep 29, 2026

PyJWT BOM Bypass

Source severity: HIGH / 0

EcosystemPackageAffected rangeFirst patched
pipPyJWT= 2.13.02.14.0

Original records & references

PUBLISHED 2026-09-29T19:14:00-04:00
MODIFIED 2026-09-29T19:14:02-04:00
INGESTED 2026-10-06T11:43:08-04:00