← Volver al buscador de CVEs

CVE-2026-48522

PyJWT

Descripción

PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib-s default OpenerDirector registering HTTPHandler, HTTPSHandler, FTPHandler, FileHandler, and DataHandler. There is currently no documented option to restrict which schemes PyJWKClient will fetch. If an application-s jku URL ingestion path accepts attacker-influenced URLs (e.g., from JWT header, configuration file, OAuth flow parameter), the attacker can cause PyJWKClient to read arbitrary local files via file:// (SSRF on local filesystem), cause PyJWKClient to attempt FTP / data-URI fetches (broader SSRF surface), or forge tokens that PyJWT verifies as valid. The library does not directly return non-HTTP(S) URI contents to the attacker; the chained -plant a JWKS to forge tokens- scenario described in the original report requires additional application-layer flaws (attacker write access to a filesystem path, untrusted jku ...

CVSS 4.2EPSS 0.22200000000000003%Riesgo 0.43
Ver fuente
Publicación
2026-05-28 16:16:29
Versiones afectadas
<2.13.0
Tipo
Package
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N