OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-103001

MEDIUM · CVSS 6.5 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The vulnerability in PyJWT affects versions 2.11.0 through 2.13.0, where the `_merge_options()` method can unintentionally modify a mutable options mapping when signature verification is disabled. This can lead to the acceptance of signed tokens with invalid claims during subsequent decode operations if the same mapping is reused, potentially allowing unauthorized access. Developers and organizations using PyJWT for authentication should prioritize addressing this issue to ensure the integrity of their token validation processes.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-103001
Severity
MEDIUM
CVSS
6.5
EPSS
0.24%

Original NVD Description

PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses that same mapping for a later decode() or decode_complete() call and changes verify_signature to true, the mapping can retain false values for expiration, not-before, issued-at, audience, issuer, subject, and JWT ID checks. A signed token with invalid registered claims can then be accepted without disabling signature verification, but applications that create a fresh options mapping for each call are not affected.

Related CVEs

Other vulnerabilities affecting the same vendor(s)