GHSA-x33g-cr3x-6449: PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion
Summary
PyJWT has a vulnerability where it accepts OKP private keys (a type of cryptographic key used in EdDSA signatures) that are internally inconsistent: the declared public key component doesn't match the one derived from the private key component. This allows an attacker to create a malicious key where PyJWT performs cryptographic operations with the attacker's private key while the key appears to belong to a legitimate user, potentially allowing stolen access tokens to be misused in DPoP (proof-of-possession) integrations.
Solution / Mitigation
A correct import should derive the public key from the private key component and reject the JWK when it does not match the supplied public key component, as stated in the source: 'A correct import should derive the public key from `d` and reject the JWK when it does not equal the supplied `x`.' However, no specific patched version or code fix is provided in the source text.
Vulnerability Details
EPSS: 0.1%
Yes
October 5, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
Original source: https://github.com/advisories/GHSA-x33g-cr3x-6449
First tracked: October 5, 2026 at 08:00 PM
Classified by LLM (prompt v3) · confidence: 75%