CVE-2026-102267
7.4 HIGHpublic exploit availablePublished 2026-09-28 · Updated 2026-09-28
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT PyJWKClient is affected because redirect destinations are not revalidated against the JWKS trust boundary. This occurs when a configured trusted JWKS endpoint returns an attacker-influenced redirect. As a result, PyJWKClient follows the redirect and consumes the redirected response as key material. Consequently, forwarded credentials may be disclosed or verification keys may be substituted. This issue is fixed in version 2.14.0.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-200, CWE-345, CWE-918
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-61749PoC
- UNSCOREDCVE-2025-12999PoC
- UNSCOREDCVE-2026-100241
- UNSCOREDCVE-2026-100244
- MEDIUMCVE-2026-100286
- MEDIUMCVE-2026-100297
- MEDIUMCVE-2026-100373PoC
- UNSCOREDCVE-2026-100377
Related by shared AI tags and CWE weakness class. Browse the full archive.