CVE-2026-102269: PyJWT: Non-canonical signature segments enable raw-token revocation bypass
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT signature segment is affected because signature segment decoding accepts characters outside the canonical Base64URL representation. This occurs when non-Base64URL characters are appended to a valid compact JWS signature segment. As a result, base64urldecode produces the same signature bytes for different serialized segments. Consequently, raw-token revocation checks can fail to recognize an equivalent modified token. This issue is fixed in version 2.14.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PyJWTto a version that resolves this vulnerability.Fixed in 2.14.0
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments using PyJWT versions earlier than 2.14.0 are affected if they perform token revocation by comparing the raw serialized token string. The bypass relies on treating differently serialized signature segments as distinct tokens even though they decode to the same signature bytes.
What does an attacker need to exploit the revocation bypass?
An attacker needs a valid compact JWS token whose raw serialized value has been revoked, and must be able to present a modified version with non-Base64URL characters appended to its signature segment. The modified segment decodes to the same signature bytes, allowing signature validation to succeed while a raw-token revocation lookup may not match it.
What should be done if patching cannot happen immediately?
Avoid relying solely on raw serialized token strings for revocation checks. Revocation logic should account for equivalent token encodings rather than assuming each serialized token string uniquely represents its decoded signature.
How can teams determine whether their application is affected?
Check whether PyJWT is below version 2.14.0 and whether revoked tokens are identified by their complete raw compact-JWS string. Test whether appending non-Base64URL characters to a valid token's signature segment preserves successful validation while causing the revocation lookup to miss the altered string.