Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-48524

Опубликовано: 28 мая 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown kid value, with no rate limiting. Since kid comes from the unverified token header, an attacker can trigger unlimited outbound requests. The vulnerability surfaces only when a JWKS fetch fails; an attacker can attempt to provoke that with sustained unknown-kid traffic, but the outcome depends on upstream JWKS-endpoint behavior (rate limiting, transient errors) which is beyond the attacker's control. This vulnerability is fixed in 2.13.0.

A flaw was found in PyJWT, a Python library for JSON Web Token (JWT) implementation. A remote attacker can exploit this vulnerability by sending specially crafted JWTs with unknown 'kid' (key ID) values. This can force the PyJWKClient.get_signing_key() function to make an unlimited number of unrate-limited HTTP requests to the JSON Web Key Set (JWKS) endpoint. This could potentially lead to a denial of service against the JWKS endpoint, depending on its rate limiting and error handling capabilities.

Отчет

Moderate: A flaw in PyJWT, as used in Red Hat products like Ansible Automation Platform and Red Hat Satellite, allows a remote attacker to trigger an unrate-limited volume of HTTP requests to a JSON Web Key Set (JWKS) endpoint. This occurs when processing specially crafted JSON Web Tokens with unknown key IDs, potentially leading to a denial of service against the external JWKS infrastructure.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-to-dataverse-exporter-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-cuda-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-rocm-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/vllm-cpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/vllm-cuda-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2482733python-pyjwt: PyJWT: Denial of Service via unverified JSON Web Token key IDs

EPSS

Процентиль: 13%
0.00222
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
2 месяца назад

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown kid value, with no rate limiting. Since kid comes from the unverified token header, an attacker can trigger unlimited outbound requests. The vulnerability surfaces only when a JWKS fetch fails; an attacker can attempt to provoke that with sustained unknown-kid traffic, but the outcome depends on upstream JWKS-endpoint behavior (rate limiting, transient errors) which is beyond the attacker's control. This vulnerability is fixed in 2.13.0.

CVSS3: 3.7
nvd
2 месяца назад

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown kid value, with no rate limiting. Since kid comes from the unverified token header, an attacker can trigger unlimited outbound requests. The vulnerability surfaces only when a JWKS fetch fails; an attacker can attempt to provoke that with sustained unknown-kid traffic, but the outcome depends on upstream JWKS-endpoint behavior (rate limiting, transient errors) which is beyond the attacker's control. This vulnerability is fixed in 2.13.0.

msrc
12 дней назад

PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)

CVSS3: 3.7
debian
2 месяца назад

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, P ...

CVSS3: 3.7
github
около 2 месяцев назад

PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)

EPSS

Процентиль: 13%
0.00222
Низкий

5.9 Medium

CVSS3