CVE-2026-103001: CWE-471: Modification of Assumed-Immutable Data (MAID) in jpadilla pyjwt
PyJWT versions 2.11.0 through 2.13.0 contain a vulnerability in the _merge_options() method where a mutable options mapping provided by the caller can be modified improperly when verify_signature is false. This can cause the options mapping to retain false values for critical JWT claim checks in subsequent decode calls with signature verification enabled, potentially allowing acceptance of tokens with invalid claims. Applications that create a fresh options mapping for each decode call are not affected.
AI Analysis
Technical Summary
In PyJWT versions 2.11.0 through 2.13.0, the _merge_options() method modifies a caller-supplied mutable options mapping when verify_signature is false. If the same mapping is reused later with verify_signature set to true, it may retain false values for expiration, not-before, issued-at, audience, issuer, subject, and JWT ID checks. This can lead to acceptance of signed tokens with invalid registered claims despite signature verification being enabled. Applications that do not reuse the same options mapping for multiple decode calls are not impacted.
Potential Impact
The vulnerability allows an attacker to potentially bypass validation of important JWT claims such as expiration and audience if the application reuses the same mutable options mapping across decode calls with differing verify_signature settings. This could result in acceptance of tokens with invalid claims, impacting the integrity of authentication or authorization decisions. The CVSS score is 6.5 (medium severity) reflecting limited attack complexity but significant impact on integrity.
Mitigation Recommendations
No official patch or fix is indicated in the provided data. To mitigate, applications should avoid reusing the same mutable options mapping across decode or decode_complete calls, especially when toggling verify_signature between false and true. Instead, create a fresh options mapping for each call to ensure proper claim validation. Check vendor advisories for updates or patches.
CVE-2026-103001: CWE-471: Modification of Assumed-Immutable Data (MAID) in jpadilla pyjwt
Description
PyJWT versions 2.11.0 through 2.13.0 contain a vulnerability in the _merge_options() method where a mutable options mapping provided by the caller can be modified improperly when verify_signature is false. This can cause the options mapping to retain false values for critical JWT claim checks in subsequent decode calls with signature verification enabled, potentially allowing acceptance of tokens with invalid claims. Applications that create a fresh options mapping for each decode call are not affected.
CVSS v3.1
Score 6.5medium
Affected software
jpadilla
pyjwt
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In PyJWT versions 2.11.0 through 2.13.0, the _merge_options() method modifies a caller-supplied mutable options mapping when verify_signature is false. If the same mapping is reused later with verify_signature set to true, it may retain false values for expiration, not-before, issued-at, audience, issuer, subject, and JWT ID checks. This can lead to acceptance of signed tokens with invalid registered claims despite signature verification being enabled. Applications that do not reuse the same options mapping for multiple decode calls are not impacted.
Potential Impact
The vulnerability allows an attacker to potentially bypass validation of important JWT claims such as expiration and audience if the application reuses the same mutable options mapping across decode calls with differing verify_signature settings. This could result in acceptance of tokens with invalid claims, impacting the integrity of authentication or authorization decisions. The CVSS score is 6.5 (medium severity) reflecting limited attack complexity but significant impact on integrity.
Mitigation Recommendations
No official patch or fix is indicated in the provided data. To mitigate, applications should avoid reusing the same mutable options mapping across decode or decode_complete calls, especially when toggling verify_signature between false and true. Instead, create a fresh options mapping for each call to ensure proper claim validation. Check vendor advisories for updates or patches.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-09-29T20:46:08.335Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abd80292a4e24523da153fb
Added to database: 09/30/2026, 21:33:29 UTC
Last enriched: 09/30/2026, 21:47:55 UTC
Last updated: 09/30/2026, 22:12:09 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.