Vulnerability GHSA-r6x4-923q-g947
High Risk
HIGH RISK
CVSS Score: 7.4
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
5 hours ago
September 29, 2026 at 11:14 PM UTC
PyJWT BOM Bypass
2.13.0
2.13.0
Summary
PyJWT BOM Bypass
Details
Affected Package
- Package: PyJWT (
pyjwton PyPI) - Repository: https://www.google.com/url?q=https://github.com/jpadilla/pyjwt&source=gmail&ust=1781794518474000&sa=E
- Affected version: 2.13.0
- Vulnerability class: Algorithm confusion / patch bypass
PoC Sketch (pseudocode — not a weaponized payload)
# 1. Attacker obtains RSA public key JWK (e.g., from /jwks.json endpoint)
# and prepends a UTF-8 BOM byte sequence before the JSON opening brace.
# 2. Attacker signs a JWT using HS256, with the BOM-prefixed JWK as the secret.
# 3. Attacker submits the forged token to a verifier that:
# - accepts algorithms=["HS256", "RS256"]
# - holds the same RSA public key as raw bytes (BOM-prefixed key file)
# 4. PyJWT 2.13.0 accepts the token because the BOM causes the JWK
# detection check to be skipped — the RSA JWK bytes become a valid HMAC key.
# Result: arbitrary claims (role, sub, etc.) accepted by the verifier.
Suggested Fix
Option A (minimal): Replace lstrip() with an explicit strip of known BOM prefixes before the JSON detection check:
# Strip common BOM prefixes in addition to ASCII whitespace
BOM_PREFIXES = (b"\xef\xbb\xbf", b"\xff\xfe", b"\xfe\xff")
stripped = key_bytes
for bom in BOM_PREFIXES:
if stripped.startswith(bom):
stripped = stripped[len(bom):]
break
stripped = stripped.lstrip()
Option B (more robust): Use json.loads() as the detection mechanism instead of a byte-prefix check, so encoding variants and whitespace are handled by the JSON parser:
try:
test_obj = json.loads(key_bytes.strip())
if isinstance(test_obj, dict) and "kty" in test_obj:
raise InvalidKeyError("The specified key is an asymmetric key...")
except (ValueError, UnicodeDecodeError):
pass
Option B is preferred because it is resilient to any future encoding variant.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
4 hours ago
PyJWT: PyJWK accepts empty HMAC keys, bypassing PyJWT's empty-key validation
2.13.0 GHSA-9j54-fg26-wv3r
2.13.0 GHSA-9j54-fg26-wv3r
Medium Risk
4 hours ago
PyJWT: Uncaught RecursionError in jwt.decode() on deeply nested token header
2.13.0 GHSA-8wjv-2p76-3863
2.13.0 GHSA-8wjv-2p76-3863
Medium Risk
5 hours ago
PyJWT: Non-canonical signature segments enable raw-token revocation bypass
0.1.1 - 2.13.0 GHSA-hxm8-2xgr-2p9m
0.1.1 - 2.13.0 GHSA-hxm8-2xgr-2p9m
Critical
5 hours ago
PyJWT: Asymmetric-PEM detection bypass: whitespace/line-ending-mutated public keys skip the HS/asymmetric confusion guard
0.1.1 - 2.13.0 GHSA-ffc3-869f-jxw9
0.1.1 - 2.13.0 GHSA-ffc3-869f-jxw9
High Risk
5 hours ago
PyJWT accepts public JWK containers as HMAC secrets
2.13.0 GHSA-w2cx-738m-mc7w
2.13.0 GHSA-w2cx-738m-mc7w
Impacted packages
Timeline
Published
5 hours ago
September 29, 2026 at 11:14 PM UTC
Fixed (2.14.0)
18 days ago
September 11, 2026 at 01:11 PM UTC
Last Modified
4 hours ago
September 29, 2026 at 11:30 PM UTC