Vulnerability Details CVE-2026-101918
PyJWT is a Python implementation of JSON Web Token standards. From 2.0.0a1 until 2.15.0, PyJWT PyJWKClient.get_signing_key_from_jwt is affected because payload parser catches ValueError but not RecursionError. This occurs when an attacker-controlled recursively nested payload reaches json.loads. As a result, documented PyJWT exception handling does not contain the failure. Consequently, an unauthenticated request can raise an exception that may produce an HTTP 500 response. The advisory-defined affected implementation also includes jwt/api_jwt.py, verify_signature=False. This issue is fixed in version 2.15.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 19.9%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2026-101918
-
cpe:2.3:a:pyjwt_project:pyjwt:2.0.0
-
cpe:2.3:a:pyjwt_project:pyjwt:2.0.1
-
cpe:2.3:a:pyjwt_project:pyjwt:2.1.0
-
cpe:2.3:a:pyjwt_project:pyjwt:2.10.0
-
cpe:2.3:a:pyjwt_project:pyjwt:2.10.1
-
cpe:2.3:a:pyjwt_project:pyjwt:2.11.0
-
cpe:2.3:a:pyjwt_project:pyjwt:2.12.0
-
cpe:2.3:a:pyjwt_project:pyjwt:2.12.1
-
cpe:2.3:a:pyjwt_project:pyjwt:2.13.0
-
cpe:2.3:a:pyjwt_project:pyjwt:2.2.0
-
cpe:2.3:a:pyjwt_project:pyjwt:2.3.0
-
cpe:2.3:a:pyjwt_project:pyjwt:2.4.0
-
cpe:2.3:a:pyjwt_project:pyjwt:2.5.0
-
cpe:2.3:a:pyjwt_project:pyjwt:2.6.0
-
cpe:2.3:a:pyjwt_project:pyjwt:2.7.0
-
cpe:2.3:a:pyjwt_project:pyjwt:2.8.0
-
cpe:2.3:a:pyjwt_project:pyjwt:2.9.0