{"id":"GHSA-9v7f-9g4p-ffgj","summary":"PyJWT: PyJWKClient follows redirects when fetching JWKS","details":"### Summary\n\nPyJWT 2.13.0 `PyJWKClient` followed HTTP redirects while fetching a JWKS,\nwithout validating the redirect destination. A configured trusted endpoint\ncould therefore redirect the client to a different host.\n\n### Impact\n\nWhen an application uses `PyJWKClient` with caller-supplied request headers and\nan attacker can influence the configured endpoint's response, the redirected\nrequest could expose those headers and the redirected response could be used as\nauthoritative key material. This could cause JWKS trust poisoning and, in\naffected mixed-configuration applications, forged JWT acceptance. The issue\nrequires an attacker-influenced redirect from the configured JWKS endpoint; it\nis not triggered by a token `kid` alone.\n\n### Affected versions\n\nPyJWT `\u003c= 2.13.0`.\n\n### Fix\n\nThe issue is fixed on `master` in commit\n[`0a795b8e1f6ef08f634aa7086fc41cc6d5ce3e56`](https://github.com/jpadilla/pyjwt/commit/0a795b8e1f6ef08f634aa7086fc41cc6d5ce3e56).\n`PyJWKClient` now disables automatic redirects for JWKS fetches. Regression\ntests verify that a redirect is rejected without contacting its destination,\nwhile normal fetches, headers, caching, errors, timeouts, and SSL context remain\ncovered.\n\nThe fix is present in the unreleased development branch. The patched version\nwill be recorded after a released PyJWT 2.x version containing the fix is\nconfirmed.\n\n### Credit\n\nCredit: the original reporter of GHSA-9v7f-9g4p-ffgj. Additional redirect\nheader-leak and cache-poisoning evidence from the newer duplicate report\nGHSA-43g3-98cx-x446 is preserved in the duplicate record and informed this\ncanonical advisory update.\n\n## Maintainer update — 2026-09-11\n\nThe verified fix for this advisory is included in PyJWT 2.14.0, released on 2026-09-11 and available on PyPI. PyJWT 2.14.0 is the first release containing the fix. This advisory is now published with 2.14.0 recorded as the patched version.","aliases":["CVE-2026-102267"],"modified":"2026-09-29T23:30:03.872305369Z","published":"2026-09-29T23:15:00Z","database_specific":{"nvd_published_at":"2026-09-28T21:17:14Z","cwe_ids":["CWE-200","CWE-345","CWE-918"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-29T23:15:00Z"},"references":[{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-9v7f-9g4p-ffgj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-102267"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/commit/0a795b8e1f6ef08f634aa7086fc41cc6d5ce3e56"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/releases/tag/2.14.0"}],"affected":[{"package":{"name":"pyjwt","ecosystem":"PyPI","purl":"pkg:pypi/pyjwt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.14.0"}]}],"versions":["0.1.1","0.1.2","0.1.3","0.1.4","0.1.5","0.1.6","0.1.7","0.1.8","0.1.9","0.2.0","0.2.1","0.2.3","0.3.0","0.3.1","0.3.2","0.4.0","0.4.1","0.4.2","0.4.3","1.0.0","1.0.1","1.1.0","1.3.0","1.4.0","1.4.1","1.4.2","1.5.0","1.5.1","1.5.2","1.5.3","1.6.0","1.6.1","1.6.3","1.6.4","1.7.0","1.7.1","2.0.0","2.0.0a1","2.0.0a2","2.0.1","2.1.0","2.10.0","2.10.1","2.11.0","2.12.0","2.12.1","2.13.0","2.2.0","2.3.0","2.4.0","2.5.0","2.6.0","2.7.0","2.8.0","2.9.0"],"database_specific":{"last_known_affected_version_range":"\u003c= 2.13.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-9v7f-9g4p-ffgj/GHSA-9v7f-9g4p-ffgj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}