CVE-2026-102266

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.from_jwk is affected because PyJWK verification path used the decoded key without applying prepare_key validation. This occurs when a trusted JWK Set contains an oct entry with an empty k value. As a result, an attacker signs an HMAC token with the same zero-length key accepted by PyJWT. Consequently, forged token can carry arbitrary authenticated claims. This issue is fixed in version 2.14.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-29: 109-29
Referenced assets1 URL
Full discourse1 post
  • NewNormal Security@NewScanTeam

    NewNormal Security turns CVEs since the previous batch into new detections, every day. 𝗗𝗮𝗶𝗹𝘆 𝗖𝗩𝗘 𝗥𝗲𝗽𝗼𝗿𝘁 — 29 Sep 2026 𝗔𝗱𝗱𝗲𝗱 to NewScan 𝘁𝗼𝗱𝗮𝘆: 📦 JWT signature verification bypass — a published public key is accepted as an HMAC secret, so anyone holding it forges a valid token (PyJWT CVE-2026-102268, CVE-2026-102266) 📦 HTTP client proxy and redirect policy bypass — the app's outbound requests leave past its egress allow-list (axios CVE-2026-101898, CVE-2026-101907) 📦 Notes-app database injection — a shared document runs unvalidated SQL against the importer's notebook database (SiYuan CVE-2026-101091, CVE-2026-101092) Test your stack with NewScan — free, self-hosted: https://newnormalsecurity.com/newscan?utm_source=x&utm_medium=social&utm_campaign=daily-cve #infosec #AppSec #JWT #CSO #REDTEAM

    0000035
    6 followersView on X

Explore more