PT-2026-44398 · Pypi+1 · Pyjwt+1

·

CVE-2026-48526

·

Published

2026-05-28

·

Updated

2026-07-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PyJWT versions prior to 2.13.0
Description PyJWT is a JSON Web Token implementation in Python. When the verifier decodes JSON Web Tokens while supporting both asymmetric and HMAC algorithms, the library fails to validate the use of JSON Web Keys in the HMAC algorithm. This allows an attacker to use the issuer public key as the secret key for the HMAC algorithm.
Recommendations Update to version 2.13.0.

Exploit

Fix

Improper Authentication

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:25902
ALSA-2026:26206
CLEANSTART-2026-AZ09261
CLEANSTART-2026-CQ05396
CLEANSTART-2026-EN66750
CLEANSTART-2026-FT24360
CLEANSTART-2026-MJ28981
CLEANSTART-2026-MR94452
CLEANSTART-2026-RF67070
CLEANSTART-2026-SO50412
CLEANSTART-2026-UO85049
CLEANSTART-2026-WQ85001
CLEANSTART-2026-WU03167
CVE-2026-48526
ECHO-B75B-8A3C-C7AE
GHSA-XGMM-8J9V-C9WX
OPENSUSE-SU-2026:11024-1
OPENSUSE-SU-2026:21095-1
PYSEC-2026-179
RHSA-2026:24069
RHSA-2026:25902
RHSA-2026:26206
RHSA-2026:34160
RHSA-2026:34365
RHSA-2026:35835
RHSA-2026:35836
RHSA-2026:35837
RHSA-2026:35845
RHSA-2026:7634
SUSE-SU-2026:22138-1
SUSE-SU-2026:22170-1
SUSE-SU-2026:22220-1
SUSE-SU-2026:22238-1
SUSE-SU-2026:2626-1
SUSE-SU-2026:2627-1

Affected Products

Pyjwt
Rocky Linux