Improper Verification of Cryptographic Signature Affecting pyjwt package, versions [2.1.0,2.15.0)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.14% (3rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-PYJWT-20245319
  • published29 Sept 2026
  • disclosed28 Sept 2026
  • creditze3tar

Introduced: 28 Sep 2026

NewCVE-2026-102275  (opens in a new tab)
CWE-347  (opens in a new tab)

How to fix?

Upgrade PyJWT to version 2.15.0 or higher.

Overview

PyJWT is a Python implementation of RFC 7519.

Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature via the from_jwk function in jwt/algorithms.py when loading an OKP (Octet Key Pair) private key from a JWK. The function constructs the private key from the d parameter without verifying that the supplied public key component x matches the public key derived from d, allowing an attacker to supply a JWK where the private and public key components are inconsistent. This mismatch can be exploited to bypass signature verification, as the public key used for verification does not correspond to the private key used for signing.

CVSS Base Scores

version 4.0
version 3.1