CVE-2026-101917 Overview
CVE-2026-101917 is a resource consumption vulnerability in PyJWT, a Python implementation of the JSON Web Token (JWT) standard. The flaw exists in the get_signing_key_from_jwt function of PyJWKClient prior to version 2.14.0. When a JWT presents an unknown kid (key identifier) value, the client forces a JWKS (JSON Web Key Set) refresh without applying a negative cache or a minimum refresh interval. Attackers can send unauthenticated tokens with varying or unknown kid values to trigger repeated outbound requests to the configured JWKS endpoint. The vulnerability is tracked under [CWE-770: Allocation of Resources Without Limits or Throttling] and is fixed in PyJWT 2.14.0.
Critical Impact
Attacker-controlled JWT traffic can amplify outbound HTTP requests from the application to the JWKS provider, degrading availability of both the application and the upstream identity endpoint.
Affected Products
- PyJWT versions prior to 2.14.0
- Python applications using PyJWKClient.get_signing_key_from_jwt
- Services relying on remote JWKS endpoints for JWT signature verification
Discovery Timeline
- 2026-09-28 - CVE-2026-101917 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-101917
Vulnerability Analysis
PyJWT provides PyJWKClient to fetch and cache signing keys from a remote JWKS endpoint. When a JWT arrives with a kid header, the client looks up the matching key in its local cache. If the key is absent, the client refreshes the JWKS from the configured URL. The vulnerable implementation performs this refresh unconditionally on every cache miss. It does not record negative lookups and does not enforce a minimum interval between refreshes. An attacker can submit a stream of JWTs bearing random or fabricated kid values. Each request forces the server to issue a new outbound HTTP call to the JWKS endpoint. The result is request amplification: a single inbound request produces one full JWKS fetch, magnifying attacker bandwidth against the upstream identity provider.
Root Cause
The root cause is missing rate limiting on cache-miss handling inside get_signing_key_from_jwt. The function treats every unknown kid as legitimate cache invalidation. Without a negative cache entry or refresh throttle, the client cannot distinguish between a legitimate key rotation and adversarial probing.
Attack Vector
Exploitation requires no authentication. An unauthenticated attacker sends HTTP requests carrying JWTs with arbitrary kid values to any endpoint that invokes PyJWKClient.get_signing_key_from_jwt. Each malformed request triggers a JWKS refresh. Sustained traffic can exhaust connection pools, saturate the JWKS endpoint, and cause denial of service at the identity provider. See the GitHub Security Advisory GHSA-2gx3-rcp4-g85q and the GitHub Commit fix for implementation details.
Detection Methods for CVE-2026-101917
Indicators of Compromise
- High-frequency outbound HTTP requests from application servers to the configured JWKS endpoint
- Application logs containing repeated JWT verification failures with unknown or unique kid header values
- Elevated latency on JWT-authenticated endpoints correlated with JWKS provider slowness
Detection Strategies
- Correlate inbound JWT verification failure rates against outbound JWKS fetch rates; a near-1:1 ratio indicates exploitation
- Baseline the frequency of unique kid values observed per client IP over rolling windows
- Alert on anomalous outbound egress volume from services that use PyJWKClient
Monitoring Recommendations
- Instrument PyJWKClient calls with metrics for cache-hit, cache-miss, and JWKS refresh counts
- Forward application and reverse-proxy logs to a centralized analytics platform for correlation
- Monitor JWKS provider health and rate-limit responses (HTTP 429) as an early exploitation signal
How to Mitigate CVE-2026-101917
Immediate Actions Required
- Upgrade PyJWT to version 2.14.0 or later across all dependent services
- Inventory Python applications using PyJWKClient and confirm patched versions in production and CI pipelines
- Apply upstream rate limiting or a Web Application Firewall (WAF) rule to reject requests containing malformed or randomly varying kid values
Patch Information
The issue is fixed in PyJWT 2.14.0. The upstream patch introduces refresh throttling and negative caching for unknown kid lookups. Refer to the PyJWT 2.14.0 Release Notes and the remediation commit.
Workarounds
- Wrap PyJWKClient with a custom class that enforces a minimum refresh interval and caches negative kid lookups
- Terminate JWT validation at an API gateway or reverse proxy that rate-limits per client IP
- Pin kid values to an allowlist when the set of signing keys is known and static
# Upgrade PyJWT to the patched version
pip install --upgrade "pyjwt>=2.14.0"
# Verify installed version
python -c "import jwt; print(jwt.__version__)"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.