Skip to main content
Vulnerability Database/CVE-2026-101917

CVE-2026-101917: PyJWT JWKS Refresh DoS Vulnerability

CVE-2026-101917 is a denial of service vulnerability in PyJWT that allows attackers to amplify requests to JWKS endpoints through repeated cache misses. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-101917 Overview

CVE-2026-101917 is a resource consumption vulnerability in PyJWT, a Python implementation of the JSON Web Token (JWT) standard. The flaw exists in the get_signing_key_from_jwt function of PyJWKClient prior to version 2.14.0. When a JWT presents an unknown kid (key identifier) value, the client forces a JWKS (JSON Web Key Set) refresh without applying a negative cache or a minimum refresh interval. Attackers can send unauthenticated tokens with varying or unknown kid values to trigger repeated outbound requests to the configured JWKS endpoint. The vulnerability is tracked under [CWE-770: Allocation of Resources Without Limits or Throttling] and is fixed in PyJWT 2.14.0.

Critical Impact

Attacker-controlled JWT traffic can amplify outbound HTTP requests from the application to the JWKS provider, degrading availability of both the application and the upstream identity endpoint.

Affected Products

  • PyJWT versions prior to 2.14.0
  • Python applications using PyJWKClient.get_signing_key_from_jwt
  • Services relying on remote JWKS endpoints for JWT signature verification

Discovery Timeline

  • 2026-09-28 - CVE-2026-101917 published to NVD
  • 2026-09-30 - Last updated in NVD database

Technical Details for CVE-2026-101917

Vulnerability Analysis

PyJWT provides PyJWKClient to fetch and cache signing keys from a remote JWKS endpoint. When a JWT arrives with a kid header, the client looks up the matching key in its local cache. If the key is absent, the client refreshes the JWKS from the configured URL. The vulnerable implementation performs this refresh unconditionally on every cache miss. It does not record negative lookups and does not enforce a minimum interval between refreshes. An attacker can submit a stream of JWTs bearing random or fabricated kid values. Each request forces the server to issue a new outbound HTTP call to the JWKS endpoint. The result is request amplification: a single inbound request produces one full JWKS fetch, magnifying attacker bandwidth against the upstream identity provider.

Root Cause

The root cause is missing rate limiting on cache-miss handling inside get_signing_key_from_jwt. The function treats every unknown kid as legitimate cache invalidation. Without a negative cache entry or refresh throttle, the client cannot distinguish between a legitimate key rotation and adversarial probing.

Attack Vector

Exploitation requires no authentication. An unauthenticated attacker sends HTTP requests carrying JWTs with arbitrary kid values to any endpoint that invokes PyJWKClient.get_signing_key_from_jwt. Each malformed request triggers a JWKS refresh. Sustained traffic can exhaust connection pools, saturate the JWKS endpoint, and cause denial of service at the identity provider. See the GitHub Security Advisory GHSA-2gx3-rcp4-g85q and the GitHub Commit fix for implementation details.

Detection Methods for CVE-2026-101917

Indicators of Compromise

  • High-frequency outbound HTTP requests from application servers to the configured JWKS endpoint
  • Application logs containing repeated JWT verification failures with unknown or unique kid header values
  • Elevated latency on JWT-authenticated endpoints correlated with JWKS provider slowness

Detection Strategies

  • Correlate inbound JWT verification failure rates against outbound JWKS fetch rates; a near-1:1 ratio indicates exploitation
  • Baseline the frequency of unique kid values observed per client IP over rolling windows
  • Alert on anomalous outbound egress volume from services that use PyJWKClient

Monitoring Recommendations

  • Instrument PyJWKClient calls with metrics for cache-hit, cache-miss, and JWKS refresh counts
  • Forward application and reverse-proxy logs to a centralized analytics platform for correlation
  • Monitor JWKS provider health and rate-limit responses (HTTP 429) as an early exploitation signal

How to Mitigate CVE-2026-101917

Immediate Actions Required

  • Upgrade PyJWT to version 2.14.0 or later across all dependent services
  • Inventory Python applications using PyJWKClient and confirm patched versions in production and CI pipelines
  • Apply upstream rate limiting or a Web Application Firewall (WAF) rule to reject requests containing malformed or randomly varying kid values

Patch Information

The issue is fixed in PyJWT 2.14.0. The upstream patch introduces refresh throttling and negative caching for unknown kid lookups. Refer to the PyJWT 2.14.0 Release Notes and the remediation commit.

Workarounds

  • Wrap PyJWKClient with a custom class that enforces a minimum refresh interval and caches negative kid lookups
  • Terminate JWT validation at an API gateway or reverse proxy that rate-limits per client IP
  • Pin kid values to an allowlist when the set of signing keys is known and static
bash
# Upgrade PyJWT to the patched version
pip install --upgrade "pyjwt>=2.14.0"

# Verify installed version
python -c "import jwt; print(jwt.__version__)"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.