Bug 2542701 (CVE-2026-102275)
| Summary: | CVE-2026-102275 pyjwt: PyJWT: Token verification bypass via mismatched OKP key components | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | akhatavk, alinfoot, amctagga, anpicker, anthomas, aoconnor, aos-team-art-private, aprice, asdas, bbrownin, blitton, bniver, bparees, cahl, cmyers, dfreiber, dkeler, dnakabaa, doconnor, dpaolell, dranck, drow, dschmidt, dtrifiro, eborisov, ebourniv, eglynn, ehelms, flucifre, ggainey, gmeno, groman, hasun, ikhan, ilpinto, jburrell, jdelft, jfula, jjoyce, jlanda, jmitchel, jowilson, jpasqual, jpretori, jsamir, jschluet, jupierce, juwatts, jwong, kaycoth, kshier, lball, lbrazdil, lcouzens, lgarciaa, lhh, ljawale, ltomasbo, mbarnett, mbenjamin, mbiarnes, mburns, mdellweg, mgarciac, mhackett, mhayden, mhulan, mminar, msilmser, ngough, nmoumoul, nyancey, oezr, omaciel, ometelka, osousa, pcreech, ppalepu, ppostler, prdhamdh, ptisnovs, rbiba, rbobbitt, rchan, rekumar, rhel-process-autobot, rjohnson, sbunciak, sdoran, sghai, sidsharm, simaishi, smallamp, sostapov, sskracic, stcannon, suppawar, syedriko, thason, tmalecek, tpfromme, ttakamiy, vereddy, veshanka, vkumar, vlaad, vvoronko, watson-tool-maintainers, weaton, xdharmai, yguenane, ykashtan |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in PyJWT. When importing an Octet Key Pair (OKP) private JSON Web Key (JWK), the library does not verify that the public key component matches the private key component. In applications that accept private key parameters from proof headers, a remote attacker can exploit this discrepancy to bypass token verification and use a stolen sender-constrained token without possessing the legitimate private key.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-09-28 21:02:30 UTC
|