CVE Vulnerabilities

CVE-2026-102269

Incorrect Behavior Order: Validate Before Canonicalize

Published: Sep 28, 2026 | Modified: Oct 06, 2026
CVSS 3.x
5.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
4.8 MODERATE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT signature segment is affected because signature segment decoding accepts characters outside the canonical Base64URL representation. This occurs when non-Base64URL characters are appended to a valid compact JWS signature segment. As a result, base64url_decode produces the same signature bytes for different serialized segments. Consequently, raw-token revocation checks can fail to recognize an equivalent modified token. This issue is fixed in version 2.14.0.

Weakness

The product validates input before it is canonicalized, which prevents the product from detecting data that becomes invalid after the canonicalization step.

Affected Software

NameVendorStart VersionEnd Version
PyjwtPyjwt_project*2.14.0 (excluding)
PyjwtUbuntuupstream*

Potential Mitigations

References