Pyjwt

Vendor:

First CVE: Aug 24, 2017 · Active for 8 years

10
Total CVEs
More Total CVEs than 88% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Pyjwt over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 24, 2017
8 years ago
Most Recent CVE
May 28, 2026
58 days ago

CVE Severity & Scoring

Pyjwt10 CVEs
All CVEs352,708 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (60.0%)
High4 (40.0%)
Unknown0 (0.0%)
User Interaction
None9 (90.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None9 (90.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the librar
May 28, 20267.436NONO
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token cont
Mar 13, 20267.530NONO
PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option ("b64": false, RFC 7797), PyJWT perf
May 28, 20265.326NONO
PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called
May 28, 20265.426NONO
PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT token can choose the used signing a
May 24, 20227.525NONO
pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedl
Jul 31, 20257.024NONO
In PyJWT 1.5.0 and below the `invalid_strings` check in `HMACAlgorithm.prepare_key` does not account for all PEM encoded public keys. Specifically, the PKCS1 PEM encoded format wou
Aug 24, 20177.524NONO
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default Ope
May 28, 20264.223NONO
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown ki
May 28, 20263.722NONO
pyjwt is a JSON Web Token implementation in Python. An incorrect string comparison is run for `iss` checking, resulting in `"acb"` being accepted for `"_abc_"`. This is a bug intro
Nov 29, 20247.522NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Pyjwt

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.10.117.00.2%00
2.10.017.50.8%00