Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-39227

24
FAUCET Score

CVE-2022-39227 is a critical authentication bypass vulnerability (CWE-290) affecting python-jwt versions prior to 3.3.4, allowing attackers to arbitrarily forge JWT contents without a secret key. This can lead to identity spoofing, session hijacking, or authentication bypass. With a CVSS score of 9.1 (CRITICAL), the vulnerability is easily exploitable over the network with low attack complexity and no user interaction, resulting in high confidentiality and integrity impacts. While there is no evidence of active exploitation, public exploit code, or significant community discussion, immediate upgrade to version 3.3.4 is recommended as there are no known workarounds.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.0.0, < 3.3.4CPE matchmatch criteria
cpe:2.3:a:python-jwt_project:python-jwt:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
3.98%
Probability of exploitation in next 30 days
EPSS Percentile
89.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0398 is in the 82nd percentile among its peer group of 36,862 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 18603-16820Fixed in: 2.4.0-2
microsoftpatch availablevia msrc
Product: cm1 python-jwt 2.4.0-2 on CBL Mariner 1.0Fixed in: 2.4.0-2
microsoftpatch availablevia msrc
Product: 20159-17084Fixed in: 2.8.0-2
microsoftpatch availablevia msrc
Product: azl3 python-jwt 2.8.0-2 on Azure Linux 3.0Fixed in: 2.8.0-2
microsoftpatch availablevia msrc
Product: cbl2 python-jwt 2.4.0-2 on CBL Mariner 2.0Fixed in: 2.4.0-2
microsoftpatch availablevia msrc
Product: 18604-16823Fixed in: 2.4.0-2
pippatch availablevia ghsa
Product: python-jwtFixed in: 3.3.4
redhatno patchvia redhat_api
Product: Red Hat Storage 3Fixed in: python-jwt
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 13 (Queens)Fixed in: python-jwt
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 4Fixed in: python-jwt

Vendor Advisories (3)

redhatCVE-2022-39227Important

python-jwt: token forgery with new claims

Sep 23, 2022
pipGHSA-5p8v-58qm-c7fpcritical

python-jwt vulnerable to token forgery with new claims

Sep 21, 2022
microsoft2022-Sep/CVE-2022-39227Critical

Python-jwt subject to Authentication Bypass by Spoofing

Sep 13, 2022

References

github.com / davedoesdev/python-jwt/commit/88ad9e67c53aa5f7c43ec4aa52ed34b7930068c9
Patch
github.com / davedoesdev/python-jwt/security/advisories/GHSA-5p8v-58qm-c7fp
PatchThird Party Advisory
github.com / pypa/advisory-database/blob/main/vulns/python-jwt/PYSEC-2022-259.yaml
Third Party Advisory
vicarius.io / vsociety/posts/authentication-bypass-in-python-jwt