OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102275

MEDIUM · CVSS 6.5 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability affects versions 2.1.0 to 2.15.0 of PyJWT, specifically in the OKPAlgorithm.from_jwk function, where improper validation of the JWK components allows an attacker to exploit discrepancies between the public and private keys. This could enable unauthorized use of stolen tokens, potentially compromising the integrity of token-based authentication systems. Organizations using affected versions of PyJWT should prioritize upgrading to version 2.15.0 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102275
Severity
MEDIUM
CVSS
6.5
EPSS
0.14%

Original NVD Description

PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in jwt/algorithms.py is affected because private-JWK import path does not compare the public key derived from d with x. This occurs when an OKP private JWK supplies non-corresponding x and d components. As a result, identity derived from x can differ from operations performed with d. Consequently, if an integration also accepts private key parameters from a proof header without rejecting them, an attacker may use a stolen sender-constrained token without the legitimate private key. This issue is fixed in version 2.15.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)