Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gvp8-978c-rx2q | PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse |
Tue, 06 Oct 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 Oct 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jpadilla
Jpadilla pyjwt |
|
| Vendors & Products |
Jpadilla
Jpadilla pyjwt |
Thu, 01 Oct 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-358 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 30 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses that same mapping for a later decode() or decode_complete() call and changes verify_signature to true, the mapping can retain false values for expiration, not-before, issued-at, audience, issuer, subject, and JWT ID checks. A signed token with invalid registered claims can then be accepted without disabling signature verification, but applications that create a fresh options mapping for each call are not affected. | |
| Title | PyJWT.decode() reintroduces options-dict mutation, enabling silent claim-verification bypass on dict reuse | |
| Weaknesses | CWE-471 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-05T23:47:32.912Z
Reserved: 2026-09-29T20:46:08.335Z
Link: CVE-2026-103001
Updated: 2026-10-05T23:47:27.875Z
Status : Awaiting Analysis
Published: 2026-09-30T22:16:33.537
Modified: 2026-10-06T00:16:32.513
Link: CVE-2026-103001
OpenCVE Enrichment
Updated: 2026-10-01T05:45:16Z
-
CWE-471
Modification of Assumed-Immutable Data (MAID)
Github GHSA