Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in the PyJWT library allows an attacker to create forged tokens with arbitrary claims by exploiting a flaw in how cryptographic keys are processed. This could enable unauthorized access or data manipulation if the affected library is used in authentication or authorization systems.
- Forged tokens can bypass security checks.
- Impacts applications using this token library.
- Confirm relevance and potential exposure.
Attack Path
How an attacker could exploit the issue
An attacker could forge a token by exploiting how PyJWT verifies JWK Sets. If a trusted JWK Set includes an entry for an HMAC key (`oct`) with an empty value, PyJWT might incorrectly process this key. This allows an attacker to sign a token using this empty key, and because the verification process bypasses proper key validation, the forged token could be accepted as legitimate, granting unauthorized access to claims.
- Entry condition: Trusted JWK Set contains an empty HMAC key.
- Trigger point: PyJWK verification of an HMAC token.
- Resulting risk: Forged tokens can carry arbitrary authenticated claims.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, an attacker could forge tokens with arbitrary authenticated claims by exploiting a weakness in how PyJWT handles JWK Set verification with empty 'k' values. This could impact systems that rely on these tokens for authentication and authorization.
- Token integrity and authenticity.
- An attacker signs tokens with a zero-length key.
- Forged tokens may bypass authentication.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in PyJWT affects applications that use HMAC-based JSON Web Tokens (JWTs) for authentication or authorization. Application owners and platform teams are primarily responsible for identifying and mitigating this risk. The immediate first step is to inventory all systems using the affected versions of PyJWT, confirm if they are exposed to untrusted JWK Sets, and then plan remediation.
- Application owners should own the remediation.
- Verify all affected PyJWT instances.
- Plan remediation based on exposure.