Impact
The vulnerability is a RecursionError in jwt.decode() that is not caught by the library’s error handling. An attacker can send a deeply nested token header, causing json.loads to raise a RecursionError, which propagates out of PyJWT’s documented error hierarchy. The result is a request‑level failure that manifests as an HTTP 500 error. This flaw allows unauthenticated users to disrupt service and is identified as a CWE‑674 issue.
Affected Systems
The affected product is PyJWT, version 2.13.0 through 2.13.x. Any deployment of PyJWT that has not yet applied the 2.14.0 fix is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. The most likely attack vector is an unauthenticated user sending a malformed, deeply nested token to an application that decodes it. Exploitation does not require privileged access but can cause application crashes and denial of service.
OpenCVE Enrichment