CVE-2026-102275: Public/Private Key Identity Confusion in PyJWT OKP JWK Processing
Vulnerability ID: CVE-2026-102275
CVSS Score: 6.5
Published: 2026-10-05
CVE-2026-102275 (GHSA-x33g-cr3x-6449) is a public/private key identity confusion vulnerability in PyJWT versions 2.1.0 through 2.14.0. When importing Octet Key Pair (OKP) JSON Web Keys (JWKs) representing Ed25519 or Ed448 curves, PyJWT fails to verify that the public parameter 'x' matches the private parameter 'd'. An attacker can construct a hybrid JWK combining a victim's public key with the attacker's private key. In protocols like DPoP that bind sessions via public key thumbprints, this allows the attacker to authenticate as the victim while signing proofs with their own private key, fully bypassing sender-constrained security guarantees.
TL;DR
PyJWT fails to verify that the public and private parameters of an imported OKP (Ed25519/Ed448) JWK belong to the same key pair. This allows attackers to forge a hybrid key containing a victim's public key and their own private key, bypassing cryptographic token bindings such as DPoP.
⚠️ Exploit Status: POC
Technical Details
- Vulnerability ID: CVE-2026-102275
- CWE ID: CWE-345 (Insufficient Verification of Data Authenticity)
- Attack Vector: Network (Unauthenticated)
- CVSS v3.1 Score: 6.5 (Medium)
- Exploit Status: Proof of Concept (PoC) available
- CISA KEV Status: Not Listed
- Primary Impact: Authentication Bypass / Security Token Hijacking
Affected Systems
- PyJWT
-
pyjwt: >= 2.1.0, < 2.15.0 (Fixed in:
2.15.0)
Code Analysis
Commit: 3cd9cee
Fix validation of OKP JWK keys by ensuring derived public key matches the public parameter x.
Exploit Details
- GitHub Security Advisory: Advisory text containing detailed information about the vulnerability mechanics and fix.
Mitigation Strategies
- Upgrade the pyjwt package to version 2.15.0 or higher.
- Implement request-filtering middleware to reject JWKs in HTTP headers that contain the private key parameter 'd'.
- Disable EdDSA and OKP algorithms in PyJWT decode routines if Ed25519/Ed448 are not actively used.
Remediation Steps:
- Execute 'pip install --upgrade pyjwt>=2.15.0' in your project environment.
- Verify the installation using 'python -c "import jwt; print(jwt.version)"'.
- Inspect the application codebase for occurrences of 'OKPAlgorithm' or jwt decode configurations containing 'EdDSA'.
- Add explicit schema validation to clean client-supplied JWS headers prior to token signature validation.
References
- GitHub Security Advisory GHSA-x33g-cr3x-6449
- Fix Commit in GitHub Repository
- PyJWT Release 2.15.0
- NVD - CVE-2026-102275
- CVE Record
Read the full report for CVE-2026-102275 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)