Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-102266

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.from_jwk is affected because PyJWK verification path used the decoded key without applying prepare_key validation. This occurs when a trusted JWK Set contains an oct entry with an empty k value. As a result, an attacker signs an HMAC token with the same zero-length key accepted by PyJWT. Consequently, forged token can carry arbitrary authenticated claims. This issue is fixed in version 2.14.0.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 6.3%
CVSS Severity
CVSS v3 Score 7.4


Contact Us

Shodan ® - All rights reserved