AZL-105642

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105642.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-105642
Upstream
Published
2026-09-30T22:16:33Z
Modified
2026-10-03T14:16:38Z
Summary
CVE-2026-103001 affecting package python-jwt 2.13.0-1
Details

PyJWT is a Python implementation of JSON Web Token standards. From 2.11.0 through 2.13.0, PyJWT's PyJWT._merge_options() method can modify a caller-supplied mutable options mapping when verify_signature is false. If an application reuses that same mapping for a later decode() or decode_complete() call and changes verify_signature to true, the mapping can retain false values for expiration, not-before, issued-at, audience, issuer, subject, and JWT ID checks. A signed token with invalid registered claims can then be accepted without disabling signature verification, but applications that create a fresh options mapping for each call are not affected.

References

Affected packages

Azure Linux:3 / python-jwt

Package

Name
python-jwt
Purl
pkg:rpm/azure-linux/python-jwt

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.13.0-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105642.json"