cbcvebase.
CVE-2026-48524
published 2026-05-28

CVE-2026-48524: PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every…

PriorityP419low3.7CVSS 3.1
AVNACHPRNUINSUCNINAL
EPSS
0.34%
26.2th percentile
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown kid value, with no rate limiting. Since kid comes from the unverified token header, an attacker can trigger unlimited outbound requests. The vulnerability surfaces only when a JWKS fetch fails; an attacker can attempt to provoke that with sustained unknown-kid traffic, but the outcome depends on upstream JWKS-endpoint behavior (rate limiting, transient errors) which is beyond the attacker's control. This vulnerability is fixed in 2.13.0.

Affected

73 ranges· showing 25
VendorProductVersion rangeFixed in
ansible-automation-platform-24lightspeed-rhel8
ansible-automation-platform-25ee-supported-rhel8
ansible-automation-platform-25lightspeed-chatbot-rhel8
ansible-automation-platform-25lightspeed-rhel8
ansible-automation-platform-26controller-rhel9
ansible-automation-platform-26eda-controller-rhel9
ansible-automation-platform-26ee-supported-rhel9
ansible-automation-platform-26gateway-rhel9
ansible-automation-platform-26hub-rhel9
ansible-automation-platform-26lightspeed-chatbot-rhel9
ansible-automation-platform-26lightspeed-rhel9
ansible-automation-platform-26mcp-tools-rhel9
ansible-automation-platform-tech-previewmetrics-service-rhel9
ansible-automation-platformautomation-dashboard-rhel9
fence-agentsfence-agents
jpadillapyjwt< 2.13.02.13.0
llvmllvm
mtamta-solution-server-rhel9
openshift-lightspeedlightspeed-ocp-rag-rhel9
openshift-lightspeedlightspeed-service-api-rhel9
openshift-lightspeedlightspeed-to-dataverse-exporter-rhel9
pyjwt_projectpyjwt< 2.13.02.13.0
pyjwt_projectpyjwt>= 0 < 2.13.02.13.0
quayquay-rhel8
quayquay-rhel9

CVSS provenance

nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.