CVE WATCH / VULNERABILITY DETAIL

CVE-2026-103001

MEDIUMCVSS 6.5NVD feed

Published 30 September 2026 · tracked since 1 October 2026

Description

PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses that same mapping for a later decode() or decode_complete() ca

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-103001 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-103001

MEDIUMCVSS 6.5NVD feed

Published 30 September 2026 · tracked since 1 October 2026

Description

PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses that same mapping for a later decode() or decode_complete() ca

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]