chiprook
← Security
SecurityOctober 1, 2026, 10:30

CVE-2026-103001: PyJWT state pollution bypasses claim verification

PyJWT versions 2.11.0 through 2.13.0 contain a state pollution flaw in _merge_options that mutates the caller's options dictionary in place. When the same dictionary is reused for later verified decodes, expiration, audience and issuer checks stay silently disabled, allowing expired or invalid tokens to pass. Fixed in 2.14.0; CVSS 6.5 with a public PoC.

CVE-2026-103001: PyJWT state pollution bypasses claim verification
#PyJWT#Python
Read next
Security

CVE-2026-63349: Privilege Dropping Bypass and DoS in AnyIO Subprocess Module

Security

Unsloth Studio flaw let malicious AI models run Python code on inspection

Security

MCP Python SDK flaw lets malicious servers steal OAuth credentials

Science

Night skies brighten 10% a year as LED lighting adds to light pollution