CVE-2026-102267 Overview
CVE-2026-102267 affects PyJWT, a widely deployed Python implementation of the JSON Web Token (JWT) standards. Versions prior to 2.14.0 fail to revalidate redirect destinations against the JSON Web Key Set (JWKS) trust boundary in PyJWKClient. When a configured trusted JWKS endpoint returns an attacker-influenced HTTP redirect, PyJWKClient follows the redirect and consumes the response as key material. This allows attackers to substitute verification keys or capture forwarded credentials. The maintainers fixed the issue in PyJWT 2.14.0 by rejecting redirects entirely in JWKS fetches.
Critical Impact
An attacker who controls or influences the redirect response from a trusted JWKS URL can substitute JWT verification keys, enabling forged token acceptance and authentication bypass in dependent applications.
Affected Products
- PyJWT versions prior to 2.14.0
- Applications using PyJWKClient to fetch remote JWKS endpoints
- Downstream Python services relying on PyJWT for JWT signature verification
Discovery Timeline
- 2026-09-28 - CVE-2026-102267 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-102267
Vulnerability Analysis
The vulnerability resides in PyJWKClient, the component responsible for retrieving JWKS documents from remote endpoints. Applications configure PyJWKClient with a trusted JWKS URL and use the returned keys to verify inbound JWTs. Prior to 2.14.0, the client followed HTTP redirects returned by that endpoint without validating the redirect target against the original trust boundary. The redirected response was then parsed and consumed as authoritative key material. This is classified as an information exposure weakness [CWE-200], and the impact extends beyond disclosure into signature verification integrity.
Root Cause
The underlying urllib request handler used by PyJWKClient transparently followed HTTP 3xx redirects. The client performed no post-redirect origin check, so a response served from an untrusted host could be treated as if it originated from the configured JWKS URL. Any credentials or headers forwarded during the redirect chain were sent to the new destination as well.
Attack Vector
Exploitation requires an attacker to influence responses from the configured JWKS endpoint or from an intermediary capable of returning a redirect. This can occur through a compromised or misconfigured identity provider, a subdomain takeover on the JWKS host, or a network position enabling response injection. Once the redirect is followed, the attacker's JWKS is trusted, and JWTs signed with attacker-controlled keys pass verification.
from .jwk_set_cache import JWKSetCache
+class _NoRedirectHandler(urllib.request.HTTPRedirectHandler):
+ def redirect_request(
+ self,
+ req: urllib.request.Request,
+ fp: Any,
+ code: int,
+ msg: str,
+ headers: Any,
+ newurl: str,
+ ) -> None:
+ return None
+
+
class PyJWKClient:
def __init__(
self,
Source: PyJWT commit 0a795b8. The patch installs a _NoRedirectHandler that returns None from redirect_request, causing urllib to abort any redirect during JWKS retrieval.
Detection Methods for CVE-2026-102267
Indicators of Compromise
- HTTP 3xx responses returned from configured JWKS endpoints in application or proxy logs
- Outbound HTTPS requests from application servers to unexpected hosts immediately after JWKS fetch calls
- Unexpected kid (key ID) values appearing in verified JWTs that do not match the canonical identity provider
- Successful authentication events using tokens signed by keys not present in the legitimate JWKS document
Detection Strategies
- Inventory Python dependencies across services and flag any PyJWT version below 2.14.0 using software composition analysis tools
- Instrument the application layer to log the final resolved URL of every JWKS fetch and alert on host mismatches
- Monitor egress traffic from application servers for JWKS retrievals that terminate at hosts outside the approved identity provider domain list
Monitoring Recommendations
- Enable egress DNS and TLS SNI logging for services performing JWT verification and correlate with expected JWKS hostnames
- Track authentication anomalies such as sudden increases in unique kid values or token issuers in identity telemetry
- Ingest application, proxy, and identity provider logs into a centralized data lake and alert on JWKS host deviations
How to Mitigate CVE-2026-102267
Immediate Actions Required
- Upgrade PyJWT to version 2.14.0 or later in all affected Python services and rebuild container images
- Audit all configured JWKS URLs and confirm they resolve directly to the intended identity provider without redirect chains
- Rotate any signing and verification keys if evidence of a redirected JWKS fetch exists in historical logs
Patch Information
The fix is available in PyJWT 2.14.0. See the PyJWT 2.14.0 release notes, the GitHub Security Advisory GHSA-9v7f-9g4p-ffgj, and the remediation commit. The patch adds a _NoRedirectHandler that disables redirect following inside PyJWKClient.
Workarounds
- Pin JWKS retrieval to a hardened outbound proxy that rejects HTTP 3xx responses from the configured identity provider host
- Cache validated JWKS responses locally and disable dynamic refresh until the upgrade is deployed
- Restrict egress from JWT-verifying services to an allowlist containing only the canonical identity provider FQDN
# Configuration example - upgrade PyJWT to the patched release
pip install --upgrade "PyJWT>=2.14.0"
# Verify the installed version
python -c "import jwt; print(jwt.__version__)"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.