{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/pyjwt--2.13.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pyjwt_project:pyjwt:*:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-102268"},{"cvss":7.4,"id":"CVE-2022-29217"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PyJWT (\u003c= 2.13.0)","PyJWT (2.13.0)"],"_cs_severities":["critical"],"_cs_tags":["jwt","authentication-bypass","cve-2026-102268","library-vulnerability"],"_cs_type":"advisory","_cs_vendors":["PyJWT"],"content_html":"\u003cp\u003ePyJWT versions 2.13.0 and earlier contain a security bypass in the \u003ccode\u003eis_pem_format\u003c/code\u003e utility that allows asymmetric public keys to be treated as symmetric HMAC secrets. This occurs because the library's internal regex-based PEM validator is overly strict, failing to recognize PEM-formatted keys that include marker-adjacent whitespace, bare carriage returns, or single-line folding. While the \u003ccode\u003ecryptography\u003c/code\u003e library correctly parses these mutated keys, PyJWT's guard mechanism - intended to prevent CVE-2022-29217 algorithm confusion - erroneously concludes they are not asymmetric keys. If an application's \u003ccode\u003ejwt.decode\u003c/code\u003e configuration includes both HMAC (e.g., HS256) and asymmetric algorithms, an attacker can leverage the public key as an HMAC secret to mint valid tokens with arbitrary claims. This vulnerability is critical for applications that fail to follow RFC 8725 best practices regarding algorithm allow-listing.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies an application that performs JWT verification with an overly permissive algorithm allow-list containing both asymmetric (e.g., RS256/ES256) and symmetric (e.g., HS256) algorithms.\u003c/li\u003e\n\u003cli\u003eThe attacker obtains the application's public verification key.\u003c/li\u003e\n\u003cli\u003eThe attacker applies specific whitespace or line-ending mutations to the public key PEM to bypass PyJWT's \u003ccode\u003eis_pem_format\u003c/code\u003e regex validation.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a malicious JWT, using the mutated public key as the HMAC shared secret to sign the token with \u003ccode\u003ealg=HS256\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe target application receives the JWT and passes the mutated key to \u003ccode\u003ePyJWT.decode\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eHMACAlgorithm.prepare_key\u003c/code\u003e function checks the mutated key against \u003ccode\u003eis_pem_format\u003c/code\u003e, which returns \u003ccode\u003eFalse\u003c/code\u003e due to the mutation.\u003c/li\u003e\n\u003cli\u003eThe guard logic is bypassed, allowing the public key bytes to be used directly as the HMAC secret.\u003c/li\u003e\n\u003cli\u003eThe application verifies the forged token as authentic, resulting in unauthorized access or privilege escalation.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for universal token forgery, enabling an attacker to bypass authentication and impersonate any user, including high-privileged accounts. The vulnerability affects any service using PyJWT where developers have combined symmetric and asymmetric algorithms in the verification allow-list. While no active real-world incident was documented in the advisory, the potential impact is critical for any system relying on affected versions of PyJWT for identity or session management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade PyJWT to version 2.14.0 or later immediately to incorporate the fix for CVE-2026-102268.\u003c/li\u003e\n\u003cli\u003eAudit all JWT verification logic to ensure algorithm allow-lists strictly adhere to RFC 8725, explicitly separating symmetric and asymmetric key paths.\u003c/li\u003e\n\u003cli\u003eAvoid mixing HMAC and RSA/ECDSA algorithms in a single allow-list entry.\u003c/li\u003e\n\u003cli\u003eTransition to the \u003ccode\u003ePyJWK\u003c/code\u003e verification path, which enforces strict algorithm binding and is unaffected by this vulnerability.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-30T04:19:20Z","date_published":"2026-09-30T04:18:49Z","id":"https://feed.craftedsignal.io/briefs/2026-09-pyjwt-pem-bypass/","summary":"An incomplete asymmetric-key guard in PyJWT (CVE-2026-102268) allows specially formatted public keys to be used as HMAC secrets, enabling universal token forgery when applications misconfigure algorithm allow-lists.","title":"PyJWT Asymmetric-PEM Detection Bypass Leading to Algorithm Confusion","url":"https://feed.craftedsignal.io/briefs/2026-09-pyjwt-pem-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - PyJWT (\u003c= 2.13.0)","version":"https://jsonfeed.org/version/1.1"}