Skip to main content

CVE-2026-103001: CWE-471: Modification of Assumed-Immutable Data (MAID) in jpadilla pyjwt

0
Medium
VulnerabilityCVE-2026-103001cvecve-2026-103001cwe-471
Published: 09/30/2026 (09/30/2026, 21:15:12 UTC)
Source: CVE Database V5
Vendor/Project: jpadilla
Product: pyjwt

Description

PyJWT versions 2.11.0 through 2.13.0 contain a vulnerability in the _merge_options() method where a mutable options mapping provided by the caller can be modified improperly when verify_signature is false. This can cause the options mapping to retain false values for critical JWT claim checks in subsequent decode calls with signature verification enabled, potentially allowing acceptance of tokens with invalid claims. Applications that create a fresh options mapping for each decode call are not affected.

CVSS v3.1

Score 6.5medium

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N

Affected software

jpadilla

pyjwt

Affected versions
>=2.11.0 <=2.13.0
pyjwt
pkg:pypi/pyjwt
Affected versions
>=2.11.0 <=2.13.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/30/2026, 21:47:55 UTC

Technical Analysis

In PyJWT versions 2.11.0 through 2.13.0, the _merge_options() method modifies a caller-supplied mutable options mapping when verify_signature is false. If the same mapping is reused later with verify_signature set to true, it may retain false values for expiration, not-before, issued-at, audience, issuer, subject, and JWT ID checks. This can lead to acceptance of signed tokens with invalid registered claims despite signature verification being enabled. Applications that do not reuse the same options mapping for multiple decode calls are not impacted.

Potential Impact

The vulnerability allows an attacker to potentially bypass validation of important JWT claims such as expiration and audience if the application reuses the same mutable options mapping across decode calls with differing verify_signature settings. This could result in acceptance of tokens with invalid claims, impacting the integrity of authentication or authorization decisions. The CVSS score is 6.5 (medium severity) reflecting limited attack complexity but significant impact on integrity.

Mitigation Recommendations

No official patch or fix is indicated in the provided data. To mitigate, applications should avoid reusing the same mutable options mapping across decode or decode_complete calls, especially when toggling verify_signature between false and true. Instead, create a fresh options mapping for each call to ensure proper claim validation. Check vendor advisories for updates or patches.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-09-29T20:46:08.335Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6abd80292a4e24523da153fb

Added to database: 09/30/2026, 21:33:29 UTC

Last enriched: 09/30/2026, 21:47:55 UTC

Last updated: 09/30/2026, 22:12:09 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses