CVE-2026-102265: Pyjwt Project Pyjwt

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWS._load in jwt/api_jws.py is affected because parser catches ValueError but not RecursionError. This occurs when a deeply nested token header reaches json.loads. As a result, RecursionError escapes the documented PyJWT error hierarchy. Consequently, an unauthenticated malformed token can cause a request-level failure and HTTP 500. This issue is fixed in version 2.14.0.

Affected products

Published 2026-09-28. Last modified 2026-10-07.