PyJWT, Algorithm Confusion via Public JWK Container HMAC Key, CVE: Not Provided (Medium) -DC-Sep2026-2643

Listen to this Post

PyJWT 2.13.0 has incomplete algorithm-confusion defense.

The library can verify JWTs with HS256, HS384, or HS512.
It can also verify asymmetric algorithms such as RS256, ES256, or EdDSA.

Applications should not mix symmetric and asymmetric verification.

A vulnerable application allows both HS and asymmetric algorithms.
It passes raw public JWK or JWKS JSON as key=.
It also uses that same value as the HMAC secret.
A public RSA, EC, or OKP JWK is normally not secret.
An attacker who knows the public key can use it as HMAC material.
The public JWK may be wrapped in a JWKS object.

It may be nested in an array.

It may use another container form without top-level kty.
PyJWT 2.13.0 may fail to reject that container as an HMAC key.

HMACAlgorithm.prepare_key is the key preparation path.

If the public JWK reaches HMAC preparation, it can become an HMAC secret.
The attacker can then forge HS256, HS384, or HS512 tokens.
Forged claims may be accepted if the application uses the same value.

The issue requires a specific mixed-algorithm configuration.

Separate symmetric and asymmetric paths are not affected.

Following PyJWT algorithm-selection guidance avoids the issue.

The fix is in commit 801cd12 on master.

HMACAlgorithm.prepare_key now rejects public JWK container HMAC keys.

It rejects public JWK members in objects, arrays, and nested containers.

It rejects BOM and UTF variants.

It rejects recursion-limit inputs.

It recognizes escaped JSON member names.

It does not treat ordinary string values as JWKs.

Ordinary JSON secrets remain accepted byte-for-byte.

PyJWT 2.14.0 is the first release containing the fix.

PyJWT 2.14.0 was released on 2026-09-11.

The affected range is 2.13.0.

DailyCVE Form:

Platform: PyJWT
Version: 2.13.0
Vulnerability: Algorithm confusion
Severity: Medium
date: 2026-09-11

Prediction: Patch 2026-09-11

What Undercode Say:

Analytics:

pip install pyjwt==2.13.0
python -c "import jwt; print(jwt.<strong>version</strong>)"
import jwt
public_jwks = '{"keys":[{"kty":"RSA","n":"...","e":"AQAB"}]}'
token = jwt.encode({"sub":"admin"}, public_jwks, algorithm="HS256")
print(token)

Exploit: (Educational Purposes!)

Obtain public JWK/JWKS.

Craft HS256 token using raw JWKS JSON.

Send token to vulnerable endpoint.

Check accepted forged claims.

Protection: from this CVE

Upgrade PyJWT 2.14.0.

Separate algorithm paths.

Do not use JWK JSON as HMAC secret.

Restrict allowed algorithms.

Validate key types.

Impact:

Forged JWT claims.

Authentication bypass.

Privilege escalation.

Unauthorized access.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top