Bug 2542697 (CVE-2026-102273)

Summary: CVE-2026-102273 pyjwt: pyjwt: Token forgery via acceptance of public JWK containers as HMAC secrets
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: akhatavk, alinfoot, amctagga, anpicker, anthomas, aoconnor, aos-team-art-private, aprice, asdas, bbrownin, blitton, bniver, bparees, cahl, cmyers, dfreiber, dkeler, dnakabaa, doconnor, dpaolell, dranck, drow, dschmidt, dtrifiro, eborisov, ebourniv, eglynn, ehelms, flucifre, ggainey, gmeno, groman, hasun, ikhan, ilpinto, jburrell, jdelft, jfula, jjoyce, jlanda, jmitchel, jowilson, jpasqual, jpretori, jsamir, jschluet, jupierce, juwatts, jwong, kaycoth, kshier, lball, lbrazdil, lcouzens, lgarciaa, lhh, ljawale, ltomasbo, mbarnett, mbenjamin, mbiarnes, mburns, mdellweg, mgarciac, mhackett, mhayden, mhulan, mminar, msilmser, ngough, nmoumoul, nyancey, oezr, omaciel, ometelka, osousa, pcreech, ppalepu, ppostler, prdhamdh, ptisnovs, rbiba, rbobbitt, rchan, rekumar, rhel-process-autobot, rjohnson, sbunciak, sdoran, sghai, sidsharm, simaishi, smallamp, sostapov, sskracic, stcannon, suppawar, syedriko, thason, tmalecek, tpfromme, ttakamiy, vereddy, veshanka, vkumar, vlaad, vvoronko, watson-tool-maintainers, weaton, xdharmai, yguenane, ykashtan
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in PyJWT. This vulnerability allows an unauthenticated remote attacker to bypass authentication by forging arbitrary JSON Web Tokens (JWTs). When an application allows both symmetric and asymmetric algorithms, PyJWT fails to properly validate public JSON Web Key (JWK) container representations, mistakenly accepting public key material as a symmetric Hash-based Message Authentication Code (HMAC) secret. As a result, an attacker with knowledge of the public key can generate validly signed tokens with arbitrary authenticated claims.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-28 20:52:38 UTC
PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key is affected because HMAC key guard only recognizes top-level public JWK forms and misses container representations. This occurs when an application allows HMAC and asymmetric algorithms and passes a public JWK container as the raw key. As a result, public asymmetric key material is accepted as the HMAC secret. Consequently, an attacker who knows the public key can forge a token with arbitrary authenticated claims. This issue is fixed in version 2.14.0.