Dev.to Security 🔐 Cybersecurity 👁 0 📖 1 min read

CVE-2026-101918: CVE-2026-101918: Unauthenticated Denial of Service via Recursion Exhaustion in PyJWT

CVE-2026-101918: Unauthenticated Denial of Service via Recursion Exhaustion in PyJWT Vulnerability ID: CVE-2026-101918 CVSS Score: 5.3 Published: 2026-09-30 A Denial of Service (DoS) vulnerability exists in the PyJW

CVE-2026-101918: Unauthenticated Denial of Service via Recursion Exhaustion in PyJWT

Vulnerability ID: CVE-2026-101918
CVSS Score: 5.3
Published: 2026-09-30

A Denial of Service (DoS) vulnerability exists in the PyJWT library when parsing unverified token payloads containing deeply nested JSON structures. Because PyJWT fails to catch RecursionError during payload parsing, an unauthenticated remote attacker can crash the application thread or worker by sending a specially crafted token.

TL;DR

An unauthenticated remote attacker can crash Python web servers using PyJWT by transmitting a token with thousands of nested JSON brackets, triggering an uncaught RecursionError and resulting in a Denial of Service (DoS).

⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-248 / CWE-400
  • Attack Vector: Network (AV:N)
  • CVSS Score: 5.3 (Medium)
  • EPSS Score: 0.00291 (Percentile: 19.51%)
  • Impact: Denial of Service (DoS)
  • Exploit Status: Proof-of-Concept
  • KEV Status: Not Listed

Affected Systems

  • Python web applications and microservices using PyJWT versions >= 2.0.0a1 and < 2.15.0 to decode tokens pre-verification or with disabled signature validation.
  • pyjwt: >= 2.0.0a1, < 2.15.0 (Fixed in: 2.15.0)

Code Analysis

Commit: 5fde08a

Catch RecursionError during payload parsing to prevent crash

Exploit Details

  • GitHub Advisory: Exploit methodology and context details regarding unauthenticated payload recursion limits

Mitigation Strategies

  • Upgrade PyJWT to version 2.15.0 or higher.
  • Implement gateway-level validation of JWT structure to drop excessively nested payloads.
  • Apply API rate limiting and connection timeout caps on authorization endpoints.

Remediation Steps:

  1. Identify all Python execution environments utilizing PyJWT.
  2. Update dependencies inside requirement files to lock pyjwt >= 2.15.0.
  3. Verify the configuration by running the application test suite with nested JSON test cases.

References

Read the full report for CVE-2026-101918 on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.