CVE Explorer
CVE-2026-48524
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown kid value, with no rate limiting. Since kid comes from the unverified token header, an attacker can trigger unlimited outbound requests. The vulnerability surfaces only when a JWKS fetch fails; an attacker can attempt to provoke that with sustained unknown-kid traffic, but the outcome depends on upstream JWKS-endpoint be
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-755","description":"CWE-755: Improper Handling of Exceptional Conditions","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4be36615e5722ab766cdd23ad9e298460fb55a12130c839e648642d5b80ca8d9 · sha256:005403df6a570ac1… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-460","description":"CWE-460: Improper Cleanup on Thrown Exception","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4be36615e5722ab766cdd23ad9e298460fb55a12130c839e648642d5b80ca8d9 · sha256:005403df6a570ac1… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"pyjwt","vendor":"jpadilla","versions":[{"status":"affected","version":"< 2.13.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:4be36615e5722ab766cdd23ad9e298460fb55a12130c839e648642d5b80ca8d9 · sha256:005403df6a570ac1… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":3.7,"baseSeverity":"LOW","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:4be36615e5722ab766cdd23ad9e298460fb55a12130c839e648642d5b80ca8d9 · sha256:005403df6a570ac1… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-755","description":"CWE-755: Improper Handling of Exceptional Conditions","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4be36615e5722ab766cdd23ad9e298460fb55a12130c839e648642d5b80ca8d9 · sha256:005403df6a570ac1… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-460","description":"CWE-460: Improper Cleanup on Thrown Exception","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4be36615e5722ab766cdd23ad9e298460fb55a12130c839e648642d5b80ca8d9 · sha256:005403df6a570ac1… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8","tags":["x_refsource_CONFIRM"],"url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4be36615e5722ab766cdd23ad9e298460fb55a12130c839e648642d5b80ca8d9 · sha256:005403df6a570ac1… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.