CVE-2026-103001: PyJWT state pollution bypasses claim verification
PyJWT versions 2.11.0 through 2.13.0 contain a state pollution flaw in _merge_options that mutates the caller's options dictionary in place. When the same dictionary is reused for later verified decodes, expiration, audience and issuer checks stay silently disabled, allowing expired or invalid tokens to pass. Fixed in 2.14.0; CVSS 6.5 with a public PoC.
- Affects PyJWT 2.11.0–2.13.0, fixed in 2.14.0
- CVSS 6.5, public PoC available, not in CISA KEV
- exp, aud, iss, nbf, iat, sub and jti checks stay off
- Cause: in-place mutation of options dict in _merge_options
Read next
Security