External risk intelligence

PyJWT HMAC Algorithm Vulnerability Allows Token Forgery

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-102266

PyJWT is a software library used by developers to handle JSON Web Tokens within applications. While it is frequently used in internet-facing services to manage authentication and authorization, the library itself is an internal component or dependency rather than a standalone, internet-facing service, appliance, or gateway.

Pyjwt Project Pyjwt

2.13.0

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the PyJWT library allows an attacker to create forged tokens with arbitrary claims by exploiting a flaw in how cryptographic keys are processed. This could enable unauthorized access or data manipulation if the affected library is used in authentication or authorization systems.

  • Forged tokens can bypass security checks.
  • Impacts applications using this token library.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could forge a token by exploiting how PyJWT verifies JWK Sets. If a trusted JWK Set includes an entry for an HMAC key (`oct`) with an empty value, PyJWT might incorrectly process this key. This allows an attacker to sign a token using this empty key, and because the verification process bypasses proper key validation, the forged token could be accepted as legitimate, granting unauthorized access to claims.

  • Entry condition: Trusted JWK Set contains an empty HMAC key.
  • Trigger point: PyJWK verification of an HMAC token.
  • Resulting risk: Forged tokens can carry arbitrary authenticated claims.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, an attacker could forge tokens with arbitrary authenticated claims by exploiting a weakness in how PyJWT handles JWK Set verification with empty 'k' values. This could impact systems that rely on these tokens for authentication and authorization.

  • Token integrity and authenticity.
  • An attacker signs tokens with a zero-length key.
  • Forged tokens may bypass authentication.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in PyJWT affects applications that use HMAC-based JSON Web Tokens (JWTs) for authentication or authorization. Application owners and platform teams are primarily responsible for identifying and mitigating this risk. The immediate first step is to inventory all systems using the affected versions of PyJWT, confirm if they are exposed to untrusted JWK Sets, and then plan remediation.

  • Application owners should own the remediation.
  • Verify all affected PyJWT instances.
  • Plan remediation based on exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is PyJWT and why do developers use it?

PyJWT is a Python library that enables developers to encode, decode, and verify JSON Web Tokens (JWTs). These tokens are a standard way to securely transmit information—such as user identity or permissions—between parties. Because it simplifies complex cryptographic tasks like signing and verifying data, it is widely integrated into applications to manage authentication and user sessions.

What is the vulnerability in CVE-2026-102266?

This CVE involves a weakness classified as CWE-347, which relates to improper verification of cryptographic signatures. In affected versions of PyJWT, the library fails to properly validate the keys used for HMAC authentication. Specifically, it may accept an empty or zero-length key as valid. This allows an attacker to sign a token with that empty key, tricking the library into accepting the forged token as authentic.

How is this vulnerability triggered?

The issue is triggered during the token verification process when the application uses a trusted JWK (JSON Web Key) Set that contains an HMAC key with an empty value. If this specific, malformed configuration exists, the library skips necessary validation checks. Note that this bug does not occur if your system does not utilize HMAC-based tokens or if your JWK sets do not contain these specifically empty key entries.

Why should I care if my application uses PyJWT?

If your application relies on PyJWT for authentication or authorization, this flaw could allow unauthorized access. According to Halo Surface Signal, while the library is typically an internal dependency rather than a standalone, internet-facing service, it is frequently used to secure services that are exposed to the internet. If those services verify tokens using this library, the risk extends to your application's ability to protect user claims.

How do I address this PyJWT vulnerability?

Your first step is to identify all applications or services in your environment that rely on PyJWT versions 2.13.0 through 2.14.0. Once you have an inventory, coordinate with your development or platform teams to update the library to version 2.14.0 or later, which contains the fix. Prioritize systems that handle sensitive user sessions or rely on external JWK sets for verification.

References