No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 29 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-347 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 28 Sep 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jpadilla
Jpadilla pyjwt |
|
| Vendors & Products |
Jpadilla
Jpadilla pyjwt |
Mon, 28 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in jwt/algorithms.py is affected because private-JWK import path does not compare the public key derived from d with x. This occurs when an OKP private JWK supplies non-corresponding x and d components. As a result, identity derived from x can differ from operations performed with d. Consequently, if an integration also accepts private key parameters from a proof header without rejecting them, an attacker may use a stolen sender-constrained token without the legitimate private key. This issue is fixed in version 2.15.0. | |
| Title | PyJWT accepts inconsistent OKP x/d JWKs, causing public/private key identity confusion | |
| Weaknesses | CWE-345 CWE-348 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-29T13:56:09.869Z
Reserved: 2026-09-28T20:11:16.658Z
Link: CVE-2026-102275
Updated: 2026-09-29T13:55:46.936Z
Status : Awaiting Analysis
Published: 2026-09-28T21:17:15.857
Modified: 2026-09-30T19:38:27.293
Link: CVE-2026-102275
OpenCVE Enrichment
Updated: 2026-09-30T04:45:19Z