๐Ÿ” CVE Alert

CVE-2026-102275

MEDIUM 6.5

PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in jwt/algorithms.py is affected because private-JWK import path does not compare the public key derived from d with x. This occurs when an OKP private JWK supplies non-corresponding x and d components. As a result, identity derived from x can differ from operations performed with d. Consequently, if an integration also accepts private key parameters from a proof header without rejecting them, an attacker may use a stolen sender-constrained token without the legitimate private key. This issue is fixed in version 2.15.0.

CWE CWE-345 CWE-348
Vendor jpadilla
Product pyjwt
Published Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for jpadilla pyjwt

Be the first to know when new medium vulnerabilities affecting jpadilla pyjwt are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
None

Affected Versions

jpadilla / pyjwt
>= 2.1.0, < 2.15.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/jpadilla/pyjwt/security/advisories/GHSA-x33g-cr3x-6449 github.com: https://github.com/jpadilla/pyjwt/commit/3cd9ceec33ced359decbad75b413ad668ae6332c github.com: https://github.com/jpadilla/pyjwt/releases/tag/2.15.0