External risk intelligence

PyJWT PyJWKClient Redirect Vulnerability Allows Key Substitution and Credential Disclosure.

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-102267

PyJWT is a software library integrated into applications rather than a standalone, internet-facing service or appliance. While the library may be used in web applications that are internet-facing, the vulnerability requires a specific, non-standard configuration where the application is directed to a malicious or compromised JWKS endpoint. Public internet exposure of the library itself is uncommon.

Information Disclosure

Pyjwt Project Pyjwt

before 2.14.0

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the PyJWT library could allow attackers to potentially disclose credentials or substitute verification keys by exploiting improperly revalidated redirect destinations in the JWKS trust boundary. This affects applications using this library for handling JSON Web Tokens, and the primary concern is to confirm if our systems utilize the affected versions and configurations.

  • Tokens may be compromised by redirect issues.
  • Trust boundary flaws enable credential disclosure.
  • Confirm use of affected PyJWT versions.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this by tricking a system that uses PyJWT into fetching JSON Web Key Set (JWKS) data from a malicious source. If the system is configured to trust a JWKS endpoint that an attacker influences to redirect to their own controlled endpoint, the system will then process the attacker's response as valid key material. This could lead to the disclosure of sensitive credentials or the substitution of verification keys, allowing the attacker to potentially impersonate users or forge tokens.

  • Unauthenticated network access required.
  • Malicious JWKS endpoint redirect.
  • Sensitive data disclosure or key substitution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to disclose forwarded credentials or substitute verification keys when a configured trusted JWKS endpoint returns an attacker-influenced redirect. This occurs because the PyJWKClient does not revalidate redirect destinations against the JWKS trust boundary.

  • Forwarded credentials could be disclosed.
  • Attacker-influenced redirects may occur.
  • Verification keys could be maliciously substituted.

Operational Fix

Recommended remediation, mitigation, and detection steps

In a real-world scenario, application owners and platform teams are most likely responsible for addressing this vulnerability, as it affects a software library used within applications. The initial step is to identify all instances of the affected PyJWT library, confirm their reachability and business criticality, and then engage the accountable owner to plan remediation.

  • Application owners must own the issue.
  • Verify JWKS endpoint configurations first.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is PyJWT and what is it used for?

PyJWT is a Python library that enables developers to encode, decode, and verify JSON Web Tokens (JWT). These tokens are widely used in web applications for securely transmitting information, such as user identity, between parties. The PyJWKClient component specifically helps applications automatically fetch public keys from a JSON Web Key Set (JWKS) endpoint to verify the authenticity of incoming tokens.

How does CVE-2026-102267 work?

This vulnerability involves a Server-Side Request Forgery (CWE-918) and a failure to validate the trust boundary (CWE-345). When the PyJWKClient fetches public keys, it fails to verify if a redirect sent by the JWKS server remains within the trusted domain. If an attacker influences that endpoint to redirect to a malicious location, the library blindly follows it and treats the untrusted response as legitimate key material, leading to possible credential disclosure (CWE-200).

What triggers this vulnerability in PyJWT?

The issue is triggered only when a configured, trusted JWKS endpoint issues an HTTP redirect to an attacker-controlled location. Simply using PyJWT or a JWKS endpoint does not automatically expose you to this risk. If your application's JWKS configuration does not utilize redirects, or if your trusted endpoints do not return attacker-influenced redirect responses, the specific conditions required to exploit this flaw are not met.

Do I need to worry if my application is not internet-facing?

Halo Surface Signal notes that PyJWT is an integrated library rather than a standalone service, making direct internet exposure uncommon. However, the risk depends on your application's architecture. If your application internally processes JWTs from untrusted sources or relies on dynamically fetched key sets from external or third-party endpoints, the internal configuration remains the critical factor regardless of whether the service faces the public internet.

How do I address CVE-2026-102267?

The primary step is to update the PyJWT library to version 2.14.0 or later, which contains the necessary logic to revalidate redirect destinations. Before updating, identify all applications in your environment using older versions of PyJWT and audit your JWKS endpoint configurations to ensure they are secure and do not perform unexpected redirects.

References