CVE-2026-102274: PyJWT: Malformed RSA JWK aborts parsing of an entire JWK Set
PyJWT is a Python implementation of JSON Web Token standards. From 2.9.0 until 2.14.0, PyJWKSet does not catch the plain ValueError raised for malformed RSA JWK components by RSAAlgorithm.fromjwk in jwt/apijwk.py. This occurs when a JWK Set contains a malformed RSA key alongside otherwise usable keys. As a result, one malformed member aborts construction of the entire PyJWKSet. Consequently, applications can experience authentication failures or request-level denial of service. This issue is fixed in version 2.14.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PyJWTto a version that resolves this vulnerability.Fixed in 2.14.0
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Applications using PyJWT versions from 2.9.0 up to, but not including, 2.14.0 are affected when they construct a PyJWKSet from a JWK Set containing a malformed RSA key alongside usable keys.
What does an attacker need to cause impact?
An attacker needs a way to cause the application to process a JWK Set containing a malformed RSA JWK component. Processing that single malformed member causes construction of the entire PyJWKSet to abort, including otherwise usable keys.
What is the impact if the vulnerable code path is reached?
The failure can cause authentication failures or request-level denial of service. The supplied vector indicates availability impact only; no confidentiality or integrity impact is specified.
What should be done if this affects an application?
Upgrade PyJWT to version 2.14.0, which fixes the issue. If an immediate upgrade is not possible, prevent malformed RSA JWKs from being included in JWK Sets processed by the application.