Improper handling of exceptional conditions in pyjwt - #VU150518
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of exceptional conditions in PyJWKSet and RSAAlgorithm.from_jwk when parsing a JWK Set containing a malformed RSA private key. A remote attacker can provide a JWK Set containing an RSA key with an invalid private exponent to cause a denial of service.