Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-32597

30
FAUCET Score

CVE-2026-32597 affects PyJWT versions prior to 2.12.0, where the Python JSON Web Token library fails to validate the 'crit' (Critical) Header Parameter, accepting JWS tokens that should be rejected. This high-severity vulnerability (CVSS 7.5) has a network attack vector and low complexity, potentially leading to high integrity impact by allowing an attacker to bypass security controls. There is currently no evidence of active exploitation or public exploit code, though it has been mentioned in community discussions regarding remediation efforts.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.12.0CPE matchmatch criteria
cpe:2.3:a:pyjwt_project:pyjwt:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
18.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 3rd percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

matrixpatch availablevia llm_extracted
View patch
pippatch availablevia ghsa
Product: PyJWTFixed in: 2.12.0
ubuntupatch availablevia ubuntu_usn
Product: pyjwt (focal)Fixed in: 1.7.1-2ubuntu2.1+esm1
ubuntupatch availablevia ubuntu_usn
Product: pyjwt (jammy)Fixed in: 2.3.0-1ubuntu0.3
ubuntupatch availablevia ubuntu_usn
Product: pyjwt (questing)Fixed in: 2.10.1-2ubuntu0.1
ubuntupatch availablevia ubuntu_usn
Product: pyjwt (xenial)Fixed in: 1.3.0-1ubuntu0.1+esm1
ubuntupatch availablevia ubuntu_usn
Product: pyjwt (noble)Fixed in: 2.7.0-1ubuntu0.1
ubuntupatch availablevia ubuntu_usn
Product: pyjwt (bionic)Fixed in: 1.5.3+ds1-1ubuntu0.1+esm1
github_advisoryworkaround availablevia nvd_reference
View patch

Vendor Advisories (3)

ubuntuUSN-8133-1

PyJWT vulnerability

Mar 30, 2026
pipGHSA-752w-5fwx-jx9fhigh

PyJWT accepts unknown `crit` header extensions

Mar 13, 2026
matrixllm-matrix-db350899a0bf0525

PyJWT vulnerability

References

access.redhat.com / errata/RHSA-2026:10140
access.redhat.com / errata/RHSA-2026:10141
access.redhat.com / errata/RHSA-2026:10184
access.redhat.com / errata/RHSA-2026:12176
access.redhat.com / errata/RHSA-2026:13508
access.redhat.com / errata/RHSA-2026:13512
access.redhat.com / errata/RHSA-2026:13545
access.redhat.com / errata/RHSA-2026:13553
access.redhat.com / errata/RHSA-2026:13672
access.redhat.com / errata/RHSA-2026:13916
access.redhat.com / errata/RHSA-2026:17083
access.redhat.com / errata/RHSA-2026:19138
access.redhat.com / errata/RHSA-2026:19355
access.redhat.com / errata/RHSA-2026:19375
access.redhat.com / errata/RHSA-2026:19712
access.redhat.com / errata/RHSA-2026:21431
access.redhat.com / errata/RHSA-2026:21517
access.redhat.com / errata/RHSA-2026:22330
access.redhat.com / errata/RHSA-2026:24977
access.redhat.com / errata/RHSA-2026:26226
access.redhat.com / errata/RHSA-2026:37275
access.redhat.com / errata/RHSA-2026:42644
access.redhat.com / errata/RHSA-2026:6568
access.redhat.com / errata/RHSA-2026:6720
access.redhat.com / errata/RHSA-2026:6912
access.redhat.com / errata/RHSA-2026:6926
access.redhat.com / errata/RHSA-2026:8437
access.redhat.com / errata/RHSA-2026:8746
access.redhat.com / errata/RHSA-2026:8747
access.redhat.com / errata/RHSA-2026:8748
access.redhat.com / security/cve/CVE-2026-32597
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-32597.json
lists.debian.org / debian-lts-announce/2026/05/msg00008.html
github.com / jpadilla/pyjwt/security/advisories/GHSA-752w-5fwx-jx9f
ExploitMitigationVendor Advisory