CVE-2026-102272
Published 28 September 2026 · tracked since 29 September 2026
Description
PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.prepare_key in jwt/algorithms.py is affected because raw-JWK detector does not normalize accepted Unicode byte-order marks before checking for JSON. This occurs when a public JWK is prefixed with a
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-102264 LOW 3.5
- CVE-2026-102263 MEDIUM 4.7
- CVE-2026-102414 LOW 3.7
- CVE-2026-102422 HIGH 8.1
- CVE-2026-102247 MEDIUM 6.8
- CVE-2026-96326 HIGH 7.2
- CVE-2026-101858 MEDIUM 4.7
- CVE-2026-101859 MEDIUM 5.4
- CVE-2026-101860 HIGH 8.8
- CVE-2026-101280 HIGH 7.3