CVE-2026-102265: Unhandled RecursionError in PyJWT JSON Parser Leading to Denial of Service
Vulnerability ID: CVE-2026-102265
CVSS Score: 5.3
Published: 2026-09-29
An uncontrolled recursion vulnerability exists in PyJWT from version 2.13.0 to 2.14.0. The vulnerability allows remote, unauthenticated attackers to cause a Denial of Service (DoS) via crafted JWT headers that trigger stack exhaustion during JSON decoding.
TL;DR
PyJWT fails to catch RecursionError during JSON header parsing, allowing remote attackers to crash request-handling threads with malformed JWTs.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-674 (Uncontrolled Recursion)
- Attack Vector: Network
- CVSS Score: 5.3 (Medium)
- EPSS Score: 0.00291 (0.29%)
- Exploit Status: Proof of Concept
- CISA KEV Status: Not Listed
Affected Systems
- Applications utilizing PyJWT versions between 2.13.0 (inclusive) and 2.14.0 (exclusive) for JWT validation.
-
PyJWT: >= 2.13.0, < 2.14.0 (Fixed in:
2.14.0)
Code Analysis
Commit: 0657369
Handle recursive JWS headers as decode errors
@@ -357,7 +357,7 @@ def _load(self, jwt: str | bytes) -> tuple[bytes, bytes, dict[str, Any], bytes]:
try:
header: dict[str, Any] = json.loads(header_data)
- except ValueError as e:
+ except (ValueError, RecursionError) as e:
raise DecodeError(f"Invalid header string: {e}") from e
if not isinstance(header, dict):
Exploit Details
- GitHub (PyJWT Test Suite): Official reproduction code confirming stack exhaustion via highly nested brackets.
Mitigation Strategies
- Upgrade PyJWT to version 2.14.0 or later to patch the exception handling logic.
- Configure Web Application Firewalls (WAF) to filter out requests containing excessive nested bracket characters in HTTP headers.
- Add application-level token validation middleware to check the complexity and size of JWT segments prior to decoding.
Remediation Steps:
- Identify all Python environments running PyJWT version 2.13.0.
- Update the package using pip: pip install --upgrade pyjwt>=2.14.0.
- Verify the installed version using: python -c "import jwt; print(jwt.version)".
- Restart dependent application servers or container pods to ensure the new library code is loaded.
References
- GitHub Security Advisory GHSA-8wjv-2p76-3863
- Fix Commit: Handle recursive JWS headers as decode errors
- CVE-2026-102265 Record (CVE.org)
- NVD CVE-2026-102265 Detail
Read the full report for CVE-2026-102265 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)