PyJWT: Asymmetric-PEM Detection Bypass via Whitespace/Line-Ending Mutated Public Keys
PyJWT versions prior to 2.8.0 insufficiently validate PEM‑encoded asymmetric public keys, allowing whitespace or line‑ending variations to evade the HS/asymmetric confusion guard. When such a mutated key is supplied with an HS256/HS384/HS512 algorithm, the library treats it as an HMAC secret, enabling an attacker who possesses the victim’s private asymmetric key to forge valid tokens. This flaw impacts any service that accepts user‑provided public keys for JWT verification or signing and can lead to authentication bypass, privilege escalation, and unauthorized API access. The issue was resolved in PyJWT 2.8.0 by replacing the custom is_pem_format() check with a try/except around cryptography.hazmat.primitives.serialization.load_pem_public_key().