CVE-2026-102270: PyJWT: ReDoS vulnerability when calling the `is_pem_format` function.
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT ispemformat is affected because lazy PEM regular expression backtracks extensively. This occurs when a certificate-like input contains repeated BEGIN markers without a matching END marker. As a result, ispemformat performs unbounded backtracking while searching for a PEM end marker. Consequently, an attacker can cause intensive CPU consumption. This issue is fixed in version 2.14.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PyJWTto a version that resolves this vulnerability.Fixed in 2.14.0
Event History
Frequently Asked Questions
What input is required to trigger the CPU consumption?
The affected function must process certificate-like input containing repeated PEM BEGIN markers without a corresponding END marker. This causes unbounded regular-expression backtracking while it searches for an end marker.
What access does an attacker need to exploit this issue?
The severity vector indicates network reachability, but exploitation has high attack complexity and requires high privileges. No user interaction is required.
Which versions should be remediated?
PyJWT versions prior to 2.14.0 are affected. Upgrade to version 2.14.0, which fixes the issue.