CVE-2026-102274: Denial of Service via Unhandled Exception in PyJWT JWK Set Parser
Vulnerability ID: CVE-2026-102274
CVSS Score: 5.9
Published: 2026-09-29
A vulnerability in PyJWT's JWK Set parsing logic allows a malformed RSA key to trigger an unhandled ValueError, leading to an application-wide or request-level Denial of Service.
TL;DR
An unhandled ValueError during RSA key recovery in PyJWT (2.9.0 - 2.13.0) crashes the entire JWK Set parser, allowing attackers to trigger a Denial of Service via malformed keys.
Technical Details
- CWE ID: CWE-755
- Attack Vector: Network
- CVSS Score: 5.9 (Medium)
- EPSS Score: 0.00352 (Percentile: 26.40%)
- Impact: Denial of Service (DoS)
- Exploit Status: Proof of Concept
- KEV Status: Not Listed
Affected Systems
- Applications using PyJWT versions 2.9.0 through 2.13.0 that process JSON Web Key Sets (JWKS).
-
pyjwt: >= 2.9.0, < 2.14.0 (Fixed in:
2.14.0)
Code Analysis
Commit: 8915570
Catch ValueError on key construction and raise InvalidKeyError
Mitigation Strategies
- Upgrade PyJWT to version 2.14.0 or higher.
- Restrict JWK Set resolution to trusted, hardcoded Identity Providers.
- Implement application-level error catching for parsing routines.
Remediation Steps:
- Identify vulnerable PyJWT installations using SCA tools or pip show.
- Update dependency declarations in requirements.txt or pyproject.toml to pyjwt>=2.14.0.
- Rebuild and redeploy application containers or virtual environments.
Read the full report for CVE-2026-102274 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)