Description
PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWS._load in jwt/api_jws.py is affected because parser catches ValueError but not RecursionError. This occurs when a deeply nested token header reaches json.loads. As a result, RecursionError escapes the documented PyJWT error hierarchy. Consequently, an unauthenticated malformed token can cause a request-level failure and HTTP 500. This issue is fixed in version 2.14.0.
Published: 2026-09-28
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch Package
AI Analysis

Impact

The vulnerability is a RecursionError in jwt.decode() that is not caught by the library’s error handling. An attacker can send a deeply nested token header, causing json.loads to raise a RecursionError, which propagates out of PyJWT’s documented error hierarchy. The result is a request‑level failure that manifests as an HTTP 500 error. This flaw allows unauthenticated users to disrupt service and is identified as a CWE‑674 issue.

Affected Systems

The affected product is PyJWT, version 2.13.0 through 2.13.x. Any deployment of PyJWT that has not yet applied the 2.14.0 fix is vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. The most likely attack vector is an unauthenticated user sending a malformed, deeply nested token to an application that decodes it. Exploitation does not require privileged access but can cause application crashes and denial of service.

Generated by OpenCVE AI on September 28, 2026 at 22:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PyJWT to version 2.14.0 or later
  • Verify that all dependent projects reference the patched library
  • Implement input validation to reject excessively nested token headers until the upgrade can be deployed

Generated by OpenCVE AI on September 28, 2026 at 22:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWS._load in jwt/api_jws.py is affected because parser catches ValueError but not RecursionError. This occurs when a deeply nested token header reaches json.loads. As a result, RecursionError escapes the documented PyJWT error hierarchy. Consequently, an unauthenticated malformed token can cause a request-level failure and HTTP 500. This issue is fixed in version 2.14.0.
Title PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header
Weaknesses CWE-674
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-28T20:48:04.664Z

Reserved: 2026-09-28T20:11:16.658Z

Link: CVE-2026-102265

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T21:17:14.077

Modified: 2026-09-28T21:17:14.077

Link: CVE-2026-102265

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T22:30:08Z

Weaknesses