CVE-2026-102271

NameCVE-2026-102271
DescriptionPyJWT is a Python implementation of JSON Web Token standards. From 2.4.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because asymmetric-key guard relies on textual markers that are absent from DER encoding. This occurs when an application mixes HMAC and asymmetric algorithms and supplies a DER public key as the shared verification key. As a result, PyJWT uses public DER bytes as an HMAC secret. Consequently, an attacker who knows the public key can forge authenticated HMAC tokens. This issue is fixed in version 2.14.0.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
pyjwt (PTS)bookworm, bookworm (security)2.6.0-1+deb12u1vulnerable
trixie (security), trixie2.10.1-2+deb13u1vulnerable
forky2.13.0-1vulnerable
sid2.15.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
pyjwtsource(unstable)2.14.0-1

Notes

https://github.com/jpadilla/pyjwt/security/advisories/GHSA-p4g4-x82p-q773
Fixed by: https://github.com/jpadilla/pyjwt/commit/2798504fa2663364573cf2d1043d8d7fef389499 (2.14.0)

Search for package or bug name: Reporting problems