19 Total advisories
19 Vulnerabilities
0 Malware
Dependency scanning
Check whether pyjwt is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.4
CVE-2026-48526
PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed
MEDIUM 5.4
CVE-2026-48523
PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keys
HIGH 7.5
CVE-2026-32597
PyJWT accepts unknown `crit` header extensions
MEDIUM 5.3
CVE-2026-48525
PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS
LOW 3.7
CVE-2026-48524
PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
MEDIUM 4.2
CVE-2026-48522
PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes
LOW 2.2
CVE-2024-53861
PyJWT Issuer field partial matches allowed
LOW 2.2
CVE-2024-53861
PyJWT Issuer field partial matches allowed
HIGH 7.4
CVE-2026-48526
CVE-2026-48526
MEDIUM 5.3
CVE-2026-48525
CVE-2026-48525
LOW 3.7
CVE-2026-48524
CVE-2026-48524
MEDIUM 5.4
CVE-2026-48523
CVE-2026-48523
MEDIUM 4.2
CVE-2026-48522
CVE-2026-48522
HIGH 7.0
CVE-2025-45768
CVE-2025-45768
HIGH 7.5
CVE-2026-32597
CVE-2026-32597
HIGH 7.5
CVE-2017-11424
PyJWT vulnerable to key confusion attacks
HIGH 7.4
CVE-2022-29217
Key confusion through non-blocklisted public key formats
UNKNOWN
CVE-2022-29217
CVE-2022-29217
UNKNOWN
CVE-2017-11424
CVE-2017-11424
Browse more PyPI advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes