← Back to Daily Briefing (#CVE-2026-102268)

PyJWT: Asymmetric-PEM Detection Bypass via Whitespace/Line-Ending Mutated Public Keys

Published October 2, 2026

PyJWT versions prior to 2.8.0 insufficiently validate PEM‑encoded asymmetric public keys, allowing whitespace or line‑ending variations to evade the HS/asymmetric confusion guard. When such a mutated key is supplied with an HS256/HS384/HS512 algorithm, the library treats it as an HMAC secret, enabling an attacker who possesses the victim’s private asymmetric key to forge valid tokens. This flaw impacts any service that accepts user‑provided public keys for JWT verification or signing and can lead to authentication bypass, privilege escalation, and unauthorized API access. The issue was resolved in PyJWT 2.8.0 by replacing the custom is_pem_format() check with a try/except around cryptography.hazmat.primitives.serialization.load_pem_public_key().

  • Vulnerability Overview
  • CVE‑2026-102268 (GHSA-ffc3-869f-jxw9) affects PyJWT < 2.8.0.
  • Root cause: jwt/utils.py’s is_pem_format() uses a strict regex that rejects PEM blocks containing spaces, tabs, carriage‑return variations, or extra blank lines.
  • Attacker supplies a mutated PEM public key (e.g., extra spaces after -----BEGIN PUBLIC KEY-----) that still loads correctly via the cryptography library.

  • Technical Details

  • The guard incorrectly classifies the mutated key as an HMAC secret when HS* algorithm is selected.
  • Underlying cryptography loader accepts the mutated PEM, so signature verification succeeds using the attacker’s known private key.
  • Patched version replaces the regex with a try/except block that attempts to load the key as a PEM public key; failure falls back to HMAC handling.

  • Impact & Exploitation

  • CVSS v3.1 score: 8.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
  • Exploitability: High – only requires ability to provide a public key (often via JWKS) and trigger JWT encoding/decoding with HS* algorithm.
  • Potential outcomes: forged tokens leading to authentication bypass, privilege escalation, unauthorized access to protected APIs or resources.

  • Detection & Mitigation

  • Review PyJWT version; upgrade to 2.8.0 or later.
  • Validate any user‑supplied keys against a strict PEM schema before passing to PyJWT.
  • Monitor JWT verification logs for unexpected HS* algorithm usage with asymmetric keys.
  • Apply the principle of least privilege: limit who can upload or modify public key material in trusted stores.

  • Conclusion

  • The bypass highlights the danger of ad‑hoc format validation versus relying on established cryptographic libraries for key parsing.
  • Prompt patching and input sanitization are essential to prevent algorithm‑confusion attacks in JWT‑based systems.
  • Organizations should inventory dependencies on PyJWT and enforce automated vulnerability scanning for similar validation gaps.

Related posts

  1. techjacksolutions.com — PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard
  2. Mondoo
  3. Secalerts
  4. Vulners
  5. Miggo
  6. Advisories
  7. Exploitsignal
  8. Github
  9. Siunam321
  10. Cascadeatlas
  11. Formulae
  12. Osv
  13. Gitlab

LINK COPIED TO CLIPBOARD