PT-2026-44397 · Pypi · Pyjwt

·

CVE-2026-48525

·

Published

2026-05-28

·

Updated

2026-07-09

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PyJWT versions 2.8.0 through 2.12.1
Description When verifying detached JWS tokens using the unencoded-payload option ("b64": false, RFC 7797), the software performs Base64URL decoding of the compact-serialization payload segment before enforcing detached-payload rules. Because the decoded payload is later discarded and replaced with the caller-provided detached payload, the middle segment can be used as a work amplifier. A remote client can provide an arbitrarily large Base64URL payload segment, forcing excessive CPU work and memory allocations regardless of whether the signature is valid. This results in an unauthenticated Denial of Service (DoS) against any endpoint verifying detached JWS.
Recommendations Update to version 2.13.0.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-AZ09261
CLEANSTART-2026-CQ05396
CLEANSTART-2026-EN66750
CLEANSTART-2026-FT24360
CLEANSTART-2026-MJ28981
CLEANSTART-2026-MR94452
CLEANSTART-2026-RF67070
CLEANSTART-2026-SO50412
CLEANSTART-2026-UO85049
CLEANSTART-2026-WQ85001
CLEANSTART-2026-WU03167
CVE-2026-48525
ECHO-C303-C499-BCC4
GHSA-W7VC-732C-9M39
OPENSUSE-SU-2026:11024-1
OPENSUSE-SU-2026:21095-1
PYSEC-2026-178
RHSA-2026:24069
SUSE-SU-2026:22138-1
SUSE-SU-2026:22170-1
SUSE-SU-2026:22220-1
SUSE-SU-2026:22238-1
SUSE-SU-2026:2626-1
SUSE-SU-2026:2627-1

Affected Products

Pyjwt