Bug 2542701 (CVE-2026-102275)

Summary: CVE-2026-102275 pyjwt: PyJWT: Token verification bypass via mismatched OKP key components
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: akhatavk, alinfoot, amctagga, anpicker, anthomas, aoconnor, aos-team-art-private, aprice, asdas, bbrownin, blitton, bniver, bparees, cahl, cmyers, dfreiber, dkeler, dnakabaa, doconnor, dpaolell, dranck, drow, dschmidt, dtrifiro, eborisov, ebourniv, eglynn, ehelms, flucifre, ggainey, gmeno, groman, hasun, ikhan, ilpinto, jburrell, jdelft, jfula, jjoyce, jlanda, jmitchel, jowilson, jpasqual, jpretori, jsamir, jschluet, jupierce, juwatts, jwong, kaycoth, kshier, lball, lbrazdil, lcouzens, lgarciaa, lhh, ljawale, ltomasbo, mbarnett, mbenjamin, mbiarnes, mburns, mdellweg, mgarciac, mhackett, mhayden, mhulan, mminar, msilmser, ngough, nmoumoul, nyancey, oezr, omaciel, ometelka, osousa, pcreech, ppalepu, ppostler, prdhamdh, ptisnovs, rbiba, rbobbitt, rchan, rekumar, rhel-process-autobot, rjohnson, sbunciak, sdoran, sghai, sidsharm, simaishi, smallamp, sostapov, sskracic, stcannon, suppawar, syedriko, thason, tmalecek, tpfromme, ttakamiy, vereddy, veshanka, vkumar, vlaad, vvoronko, watson-tool-maintainers, weaton, xdharmai, yguenane, ykashtan
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in PyJWT. When importing an Octet Key Pair (OKP) private JSON Web Key (JWK), the library does not verify that the public key component matches the private key component. In applications that accept private key parameters from proof headers, a remote attacker can exploit this discrepancy to bypass token verification and use a stolen sender-constrained token without possessing the legitimate private key.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-28 21:02:30 UTC
PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in  jwt/algorithms.py is affected because private-JWK import path does not compare the public key derived from d with x. This occurs when an OKP private JWK supplies non-corresponding x and d components. As a result, identity derived from x can differ from operations performed with d. Consequently, if an integration also accepts private key parameters from a proof header without rejecting them, an attacker may use a stolen sender-constrained token without the legitimate private key. This issue is fixed in version 2.15.0.