AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-102273.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 29, 2026

Disclosure summary

### Summary PyJWT 2.13.0 contains an incomplete defense against algorithm confusion when an application mixes symmetric and asymmetric algorithms in one verification path. A public RSA, EC, or OKP JWK can be accepted as an HMAC secret when it is wrapped in a JWKS object, nested in an array, or represented in another container form that does not expose a top-level `kty` member. ### Impact An attacker who knows the public key material can forge HS256/HS384/HS512 tokens if the application simultaneously: * allows both HS* and asymmetric algorithms; * passes raw public JWK/JWKS JSON as `key=`; and * uses that same value as the HMAC secret. This can allow forged JWT claims in affected application configurations. The issue does not affect applications that keep symmetric and asymmetric verification paths separate and follow PyJWT's algorithm-selection guidance. ### Fix status The fix is on `master` in commit `801cd12` (`fix: reject public JWK container HMAC keys`). `HMACAlgorithm.prepare_key` now rejects public JWK members found in objects, arrays, nested containers, BOM/UTF variants, and recursion-limit inputs. It also recognizes escaped JSON member names without treating ordinary strin

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-w2cx-738m-mc7w

Open original source · Updated Sep 29, 2026

PyJWT accepts public JWK containers as HMAC secrets

Source severity: HIGH / 0

EcosystemPackageAffected rangeFirst patched
pipPyJWT= 2.13.02.14.0

Original records & references

PUBLISHED 2026-09-29T19:16:55-04:00
MODIFIED 2026-09-29T19:16:55-04:00
INGESTED 2026-10-06T11:43:08-04:00