Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 29 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 28 Sep 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jpadilla
Jpadilla pyjwt |
|
| Vendors & Products |
Jpadilla
Jpadilla pyjwt |
Mon, 28 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in jwt/algorithms.py is affected because private-JWK import path does not compare the public key derived from d with x. This occurs when an OKP private JWK supplies non-corresponding x and d components. As a result, identity derived from x can differ from operations performed with d. Consequently, if an integration also accepts private key parameters from a proof header without rejecting them, an attacker may use a stolen sender-constrained token without the legitimate private key. This issue is fixed in version 2.15.0. | |
| Title | PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion | |
| Weaknesses | CWE-345 CWE-348 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-29T13:56:09.869Z
Reserved: 2026-09-28T20:11:16.658Z
Link: CVE-2026-102275
Updated: 2026-09-29T13:55:46.936Z
Status : Received
Published: 2026-09-28T21:17:15.857
Modified: 2026-09-29T14:17:19.873
Link: CVE-2026-102275
OpenCVE Enrichment
Updated: 2026-09-29T18:30:11Z