The classifier judged this item not relevant to AI security, so it is left out of lists, feeds, the API and dataset releases. If that is wrong, report a correction on this page.
GHSA-42vr-xj54-vc7v: PyJWT: Unauthenticated RecursionError DoS in pre-verification payload parse (PyJWKClient.get_signing_key_from_jwt / verify_signature=False)
- Identifiers
- CVE-2026-101918GHSA-42vr-xj54-vc7v
- Published
- Record updated
Summary
PyJWT's pre-verification payload parse in PyJWKClient.get_signing_key_from_jwt and jwt.decode with verify_signature=False catches only ValueError around json.loads, so a valid but ~20,000-level-deep JSON payload raises an uncaught RecursionError. An unauthenticated attacker can crash an auth handler with a single ~50KB token, and the JWKS endpoint response parsing in PyJWKClient.fetch_data has the same gap. The flaw affects version 2.14.0 and the current master branch.
Mitigation
Suggested fix in source, not yet confirmed as released: change `except ValueError as e:` to `except (ValueError, RecursionError) as e:` at jwt/api_jwt.py:299, and wrap json.load(response) in PyJWKClient.fetch_data with the same handling, raising PyJWKClientError.