CVE-2026-32597 affects PyJWT versions prior to 2.12.0, where the Python JSON Web Token library fails to validate the 'crit' (Critical) Header Parameter, accepting JWS tokens that should be rejected. This high-severity vulnerability (CVSS 7.5) has a network attack vector and low complexity, potentially leading to high integrity impact by allowing an attacker to bypass security controls. There is currently no evidence of active exploitation or public exploit code, though it has been mentioned in community discussions regarding remediation efforts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.12.0CPE matchmatch criteria | cpe:2.3:a:pyjwt_project:pyjwt:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.