Bug 2542697 (CVE-2026-102273)
| Summary: | CVE-2026-102273 pyjwt: pyjwt: Token forgery via acceptance of public JWK containers as HMAC secrets | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | akhatavk, alinfoot, amctagga, anpicker, anthomas, aoconnor, aos-team-art-private, aprice, asdas, bbrownin, blitton, bniver, bparees, cahl, cmyers, dfreiber, dkeler, dnakabaa, doconnor, dpaolell, dranck, drow, dschmidt, dtrifiro, eborisov, ebourniv, eglynn, ehelms, flucifre, ggainey, gmeno, groman, hasun, ikhan, ilpinto, jburrell, jdelft, jfula, jjoyce, jlanda, jmitchel, jowilson, jpasqual, jpretori, jsamir, jschluet, jupierce, juwatts, jwong, kaycoth, kshier, lball, lbrazdil, lcouzens, lgarciaa, lhh, ljawale, ltomasbo, mbarnett, mbenjamin, mbiarnes, mburns, mdellweg, mgarciac, mhackett, mhayden, mhulan, mminar, msilmser, ngough, nmoumoul, nyancey, oezr, omaciel, ometelka, osousa, pcreech, ppalepu, ppostler, prdhamdh, ptisnovs, rbiba, rbobbitt, rchan, rekumar, rhel-process-autobot, rjohnson, sbunciak, sdoran, sghai, sidsharm, simaishi, smallamp, sostapov, sskracic, stcannon, suppawar, syedriko, thason, tmalecek, tpfromme, ttakamiy, vereddy, veshanka, vkumar, vlaad, vvoronko, watson-tool-maintainers, weaton, xdharmai, yguenane, ykashtan |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in PyJWT. This vulnerability allows an unauthenticated remote attacker to bypass authentication by forging arbitrary JSON Web Tokens (JWTs). When an application allows both symmetric and asymmetric algorithms, PyJWT fails to properly validate public JSON Web Key (JWK) container representations, mistakenly accepting public key material as a symmetric Hash-based Message Authentication Code (HMAC) secret. As a result, an attacker with knowledge of the public key can generate validly signed tokens with arbitrary authenticated claims.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-09-28 20:52:38 UTC
|