DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-102274: CVE-2026-102274: Denial of Service via Unhandled Exception in PyJWT JWK Set Parser

CVE-2026-102274: Denial of Service via Unhandled Exception in PyJWT JWK Set Parser

Vulnerability ID: CVE-2026-102274
CVSS Score: 5.9
Published: 2026-09-29

A vulnerability in PyJWT's JWK Set parsing logic allows a malformed RSA key to trigger an unhandled ValueError, leading to an application-wide or request-level Denial of Service.

TL;DR

An unhandled ValueError during RSA key recovery in PyJWT (2.9.0 - 2.13.0) crashes the entire JWK Set parser, allowing attackers to trigger a Denial of Service via malformed keys.


Technical Details

  • CWE ID: CWE-755
  • Attack Vector: Network
  • CVSS Score: 5.9 (Medium)
  • EPSS Score: 0.00352 (Percentile: 26.40%)
  • Impact: Denial of Service (DoS)
  • Exploit Status: Proof of Concept
  • KEV Status: Not Listed

Affected Systems

  • Applications using PyJWT versions 2.9.0 through 2.13.0 that process JSON Web Key Sets (JWKS).
  • pyjwt: >= 2.9.0, < 2.14.0 (Fixed in: 2.14.0)

Code Analysis

Commit: 8915570

Catch ValueError on key construction and raise InvalidKeyError

Mitigation Strategies

  • Upgrade PyJWT to version 2.14.0 or higher.
  • Restrict JWK Set resolution to trusted, hardcoded Identity Providers.
  • Implement application-level error catching for parsing routines.

Remediation Steps:

  1. Identify vulnerable PyJWT installations using SCA tools or pip show.
  2. Update dependency declarations in requirements.txt or pyproject.toml to pyjwt>=2.14.0.
  3. Rebuild and redeploy application containers or virtual environments.

Read the full report for CVE-2026-102274 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)