CODE RED

P4 Verified

PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard

CVE-2026-102268 affects azl3 python-jwt 2.13.0-1 on Azure Linux 3.0. CVSS base score 9.1 (msrc). EPSS 0.00196 (percentile 0.08369), scored 2026-10-03. Fixed version: 2.13.0-1+e2. Fixed version: 2.14.0.

Summary source: template

CVE / CWE
CVE-2026-102268 /
Vendor / product
Unavailable / azl3 python-jwt 2.13.0-1 on Azure Linux 3.0
Severity
36.4
CVSS
9.1 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N · msrc
EPSS
0.00196 · percentile 0.08369 · 2026-10-03
KEV
no · added unavailable · due unavailable · ransomware use unavailable
Exploit signals
Signal evidence

Affected products

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-102268.html