DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-102265: CVE-2026-102265: Unhandled RecursionError in PyJWT JSON Parser Leading to Denial of Service

CVE-2026-102265: Unhandled RecursionError in PyJWT JSON Parser Leading to Denial of Service

Vulnerability ID: CVE-2026-102265
CVSS Score: 5.3
Published: 2026-09-29

An uncontrolled recursion vulnerability exists in PyJWT from version 2.13.0 to 2.14.0. The vulnerability allows remote, unauthenticated attackers to cause a Denial of Service (DoS) via crafted JWT headers that trigger stack exhaustion during JSON decoding.

TL;DR

PyJWT fails to catch RecursionError during JSON header parsing, allowing remote attackers to crash request-handling threads with malformed JWTs.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-674 (Uncontrolled Recursion)
  • Attack Vector: Network
  • CVSS Score: 5.3 (Medium)
  • EPSS Score: 0.00291 (0.29%)
  • Exploit Status: Proof of Concept
  • CISA KEV Status: Not Listed

Affected Systems

  • Applications utilizing PyJWT versions between 2.13.0 (inclusive) and 2.14.0 (exclusive) for JWT validation.
  • PyJWT: >= 2.13.0, < 2.14.0 (Fixed in: 2.14.0)

Code Analysis

Commit: 0657369

Handle recursive JWS headers as decode errors

@@ -357,7 +357,7 @@ def _load(self, jwt: str | bytes) -> tuple[bytes, bytes, dict[str, Any], bytes]:

         try:
             header: dict[str, Any] = json.loads(header_data)
-        except ValueError as e:
+        except (ValueError, RecursionError) as e:
             raise DecodeError(f"Invalid header string: {e}") from e

         if not isinstance(header, dict):
Enter fullscreen mode Exit fullscreen mode

Exploit Details

Mitigation Strategies

  • Upgrade PyJWT to version 2.14.0 or later to patch the exception handling logic.
  • Configure Web Application Firewalls (WAF) to filter out requests containing excessive nested bracket characters in HTTP headers.
  • Add application-level token validation middleware to check the complexity and size of JWT segments prior to decoding.

Remediation Steps:

  1. Identify all Python environments running PyJWT version 2.13.0.
  2. Update the package using pip: pip install --upgrade pyjwt>=2.14.0.
  3. Verify the installed version using: python -c "import jwt; print(jwt.version)".
  4. Restart dependent application servers or container pods to ensure the new library code is loaded.

References


Read the full report for CVE-2026-102265 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)