CVE-2026-102274 Overview
CVE-2026-102274 is a denial-of-service vulnerability in PyJWT, a widely used Python implementation of the JSON Web Token (JWT) standards. The flaw affects PyJWKSet construction in versions 2.9.0 through 2.13.x. When a JWK Set contains a malformed RSA key alongside otherwise valid keys, an uncaught ValueError from RSAAlgorithm.from_jwk aborts construction of the entire set. Applications relying on rotating JWK Sets can experience authentication failures or request-level denial of service. The issue is classified under [CWE-755: Improper Handling of Exceptional Conditions] and is fixed in PyJWT 2.14.0.
Critical Impact
A single malformed RSA JWK member can disable JWT verification across an entire application, breaking authentication for all users relying on the affected JWK Set.
Affected Products
- PyJWT 2.9.0 through 2.13.x
- Python applications using PyJWKSet for JWT signature verification
- Services consuming remote JWK Set endpoints (identity providers, OAuth/OIDC clients)
Discovery Timeline
- 2026-09-28 - CVE-2026-102274 published to NVD
- 2026-09-30 - Last updated in NVD database
Technical Details for CVE-2026-102274
Vulnerability Analysis
The vulnerability resides in jwt/api_jwk.py, where PyJWK initialization calls self.Algorithm.from_jwk(self._jwk_data) without wrapping the call in exception handling. For RSA keys, RSAAlgorithm.from_jwk raises a plain ValueError when it encounters malformed key components such as invalid base64 encoding, wrong-length modulus, or missing parameters.
PyJWKSet iterates over all keys in a set and instantiates PyJWK for each entry. Because the raw ValueError propagates unhandled, one malformed member terminates iteration and prevents construction of the entire key set. Applications that fetch JWKs from a remote identity provider then fail to verify any incoming JWTs, producing authentication errors for every request.
Root Cause
The root cause is improper handling of exceptional conditions [CWE-755]. PyJWT expected algorithm-specific from_jwk implementations to raise InvalidKeyError, but RSAAlgorithm.from_jwk raised the generic ValueError for certain malformed inputs. PyJWKSet only caught the expected exception type, so the unexpected exception aborted set construction rather than skipping the invalid key.
Attack Vector
An attacker who can influence the contents of a JWK Set consumed by a target application can trigger the condition. This includes scenarios where a compromised or misconfigured identity provider publishes a malformed RSA key, or where a downstream JWK Set proxy injects invalid entries. The attack does not require authentication or user interaction and is exploitable over the network, but requires the ability to place a malformed key into a JWK Set that the victim application retrieves.
f"Unable to find an algorithm for key: {self._jwk_data}",
) from None
- self.key = self.Algorithm.from_jwk(self._jwk_data)
+ try:
+ self.key = self.Algorithm.from_jwk(self._jwk_data)
+ except ValueError as error:
+ raise InvalidKeyError(
+ f"Unable to construct key from JWK: {error}"
+ ) from error
@staticmethod
def from_dict(obj: JWKDict, algorithm: str | None = None) -> PyJWK:
Source: GitHub Commit 8915570. The patch wraps from_jwk in a try/except ValueError and re-raises as InvalidKeyError, allowing PyJWKSet to catch and skip the malformed member.
Detection Methods for CVE-2026-102274
Indicators of Compromise
- Sudden spikes in JWT verification failures across an application after a JWK Set refresh
- Application logs containing unhandled ValueError exceptions originating from jwt/api_jwk.py
- Authentication service returning 401/403 responses for previously valid tokens after a key rotation event
Detection Strategies
- Inventory Python dependencies and flag any PyJWT installation between versions 2.9.0 and 2.13.x using pip list or Software Bill of Materials (SBOM) tooling
- Add unit tests that construct PyJWKSet from JWK Sets containing intentionally malformed RSA keys to detect vulnerable behavior
- Monitor exception telemetry for ValueError traces referencing RSAAlgorithm.from_jwk or PyJWK.__init__
Monitoring Recommendations
- Instrument application authentication middleware to emit metrics on JWK Set fetch success and per-key parsing failures
- Alert on sustained authentication failure rates that correlate with upstream JWK Set publication events
- Log the JWK Set URL, key IDs, and key types retrieved on each refresh to support forensic reconstruction
How to Mitigate CVE-2026-102274
Immediate Actions Required
- Upgrade PyJWT to version 2.14.0 or later in all Python environments verifying JWTs
- Audit application code paths that call PyJWKSet or PyJWKClient to confirm they operate on the patched library version
- Validate JWK Sets retrieved from external identity providers before passing them to PyJWT during rollout
Patch Information
The fix is available in PyJWT 2.14.0. See the GitHub Release Version 2.14.0 and the GitHub Security Advisory GHSA-w6j9-cwv2-h6wq for full details. The patch commit 8915570 in jwt/api_jwk.py catches ValueError from Algorithm.from_jwk and re-raises it as InvalidKeyError, which PyJWKSet handles by skipping the malformed entry.
Workarounds
- Pre-filter JWK Sets in application code by attempting to parse each key individually and discarding entries that raise exceptions
- Cache the last known-good JWK Set and fall back to it when a refresh produces a parse failure
- Pin identity provider trust to known key IDs to reduce exposure to injected malformed keys
# Upgrade PyJWT to the patched version
pip install --upgrade 'PyJWT>=2.14.0'
# Verify installed version
python -c "import jwt; print(jwt.__version__)"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.