PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)

Summary

CVECVE-2026-32597
StatePUBLISHED
AssignerGitHub_M
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-03-13 19:55:09 UTC
Updated2026-07-22 12:17:34 UTC
DescriptionPyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.

Risk And Classification

Primary CVSS: v3.1 7.5 HIGH from ADP

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS: 0.002690000 probability, percentile 0.187800000 (date 2026-07-22)

Problem Types: CWE-345 | CWE-863 | CWE-347 | CWE-345 CWE-345: Insufficient Verification of Data Authenticity | CWE-863 CWE-863: Incorrect Authorization | CWE-347 Improper Verification of Cryptographic Signature


VersionSourceTypeScoreSeverityVector
3.1ADPCVSS7.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
3.1[email protected]Secondary7.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
3.10b0ca135-0b70-47e7-9f44-1890c2a1c46cSecondary7.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
3.1CNADECLARED7.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CVSS v3.1 Breakdown

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Application Pyjwt Project Pyjwt All All All All

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Jpadilla Pyjwt affected < 2.12.0 Not specified
ADP Red Hat Red Hat Ansible Automation Platform 2.5 For RHEL 8 unaffected 0:4.6.28-3.el8ap * rpm Not specified
ADP Red Hat Red Hat Ansible Automation Platform 2.5 For RHEL 8 unaffected 0:2.12.1-1.el8ap * rpm Not specified
ADP Red Hat Red Hat Ansible Automation Platform 2.5 For RHEL 9 unaffected 0:4.6.28-3.el9ap * rpm Not specified
ADP Red Hat Red Hat Ansible Automation Platform 2.5 For RHEL 9 unaffected 0:2.12.1-1.el9ap * rpm Not specified
ADP Red Hat Red Hat Ansible Automation Platform 2.6 For RHEL 9 unaffected 0:4.7.11-2.el9ap * rpm Not specified
ADP Red Hat Red Hat Ansible Automation Platform 2.6 For RHEL 9 unaffected 0:2.12.1-1.el9ap * rpm Not specified
ADP Red Hat Red Hat Enterprise Linux 10 unaffected 0:4.16.0-13.el10_1.4 * rpm Not specified
ADP Red Hat Red Hat Enterprise Linux 10 unaffected 0:4.16.0-21.el10_2.1 * rpm Not specified
ADP Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support unaffected 0:4.16.0-5.el10_0.9 * rpm Not specified
ADP Red Hat Red Hat Enterprise Linux 8 unaffected 0:4.2.1-129.el8_10.25 * rpm Not specified
ADP Red Hat Red Hat Enterprise Linux 9 unaffected 0:4.10.0-110.el9_8.2 * rpm Not specified
ADP Red Hat Red Hat Enterprise Linux 9 unaffected 0:4.10.0-98.el9_7.12 * rpm Not specified
ADP Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions unaffected 0:4.10.0-43.el9_2.21 * rpm Not specified
ADP Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support unaffected 0:4.10.0-62.el9_4.24 * rpm Not specified
ADP Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support unaffected 0:4.10.0-86.el9_6.16 * rpm Not specified
ADP Red Hat Red Hat AI Inference Server 3.3 unaffected 1775680192 * rpm Not specified
ADP Red Hat Red Hat AI Inference Server 3.3 unaffected 1775680262 * rpm Not specified
ADP Red Hat Red Hat AI Inference Server 3.3 unaffected 1775749857 * rpm Not specified
ADP Red Hat Red Hat Ansible Automation Platform 2.5 unaffected 1777394109 * rpm Not specified
ADP Red Hat Red Hat Ansible Automation Platform 2.5 unaffected 1777403872 * rpm Not specified
ADP Red Hat Red Hat Ansible Automation Platform 2.6 unaffected 1777296732 * rpm Not specified
ADP Red Hat Red Hat Ansible Automation Platform 2.6 unaffected 1777391447 * rpm Not specified
ADP Red Hat Red Hat Ansible Automation Platform 2.6 unaffected 1777311120 * rpm Not specified
ADP Red Hat Red Hat Ansible Automation Platform 2.6 unaffected 1777299023 * rpm Not specified
ADP Red Hat Red Hat Ansible Automation Platform 2.6 unaffected 1777398576 * rpm Not specified
ADP Red Hat Red Hat Ansible Automation Platform 2.6 unaffected 1777387242 * rpm Not specified
ADP Red Hat Red Hat Ansible Automation Platform 2.6 unaffected 1777311601 * rpm Not specified
ADP Red Hat Red Hat Enterprise Linux AI 3.3 unaffected 1776871984 * rpm Not specified
ADP Red Hat Red Hat Enterprise Linux AI 3.3 unaffected 1776871985 * rpm Not specified
ADP Red Hat Red Hat Enterprise Linux AI 3.3 unaffected 1776872005 * rpm Not specified
ADP Red Hat Red Hat Enterprise Linux AI 3.3 unaffected 1776773390 * rpm Not specified
ADP Red Hat Red Hat Enterprise Linux AI 3.3 unaffected 1776871987 * rpm Not specified
ADP Red Hat Red Hat Enterprise Linux AI 3.3 unaffected 1776773505 * rpm Not specified
ADP Red Hat Red Hat Enterprise Linux AI 3.3 unaffected 1776938871 * rpm Not specified
ADP Red Hat Red Hat OpenShift AI 2.25 unaffected 1776338381 * rpm Not specified
ADP Red Hat Red Hat OpenShift AI 2.25 unaffected 1776343111 * rpm Not specified
ADP Red Hat Red Hat OpenShift AI 2.25 unaffected 1780069069 * rpm Not specified
ADP Red Hat Red Hat OpenShift AI 2.25 unaffected 1783696512 * rpm Not specified
ADP Red Hat Red Hat OpenShift AI 2.25 unaffected 1783616068 * rpm Not specified
ADP Red Hat Red Hat OpenShift AI 2.25 unaffected 1783998551 * rpm Not specified
ADP Red Hat Red Hat OpenShift AI 2.25 unaffected 1783664916 * rpm Not specified
ADP Red Hat Red Hat OpenShift AI 2.25 unaffected 1783615385 * rpm Not specified
ADP Red Hat Red Hat OpenShift AI 2.25 unaffected 1783664921 * rpm Not specified
ADP Red Hat Red Hat OpenShift AI 2.25 unaffected 1783696507 * rpm Not specified
ADP Red Hat Red Hat OpenShift AI 2.25 unaffected 1783615414 * rpm Not specified
ADP Red Hat Red Hat OpenShift AI 2.25 unaffected 1783998585 * rpm Not specified
ADP Red Hat Red Hat OpenShift AI 2.25 unaffected 1783664921 * rpm Not specified
ADP Red Hat Red Hat OpenShift AI 2.25 unaffected 1783615165 * rpm Not specified
ADP Red Hat Red Hat OpenShift AI 2.25 unaffected 1783664921 * rpm Not specified
ADP Red Hat Red Hat OpenShift AI 2.25 unaffected 1783615432 * rpm Not specified
ADP Red Hat Red Hat OpenShift AI 3.3 unaffected 1778264363 * rpm Not specified
ADP Red Hat Red Hat OpenShift AI 3.3 unaffected 1778600187 * rpm Not specified
ADP Red Hat Red Hat OpenShift AI 3.3 unaffected 1782472374 * rpm Not specified
ADP Red Hat Red Hat Quay 3.1 unaffected 1775169155 * rpm Not specified
ADP Red Hat Red Hat Quay 3.12 unaffected 1775253092 * rpm Not specified
ADP Red Hat Red Hat Quay 3.15 unaffected 1775169219 * rpm Not specified
ADP Red Hat Red Hat Quay 3.16 unaffected 1779204086 * rpm Not specified
ADP Red Hat Red Hat Quay 3.9 unaffected 1775169218 * rpm Not specified
ADP Red Hat Red Hat Satellite 6.18 unaffected 1780414237 * rpm Not specified
ADP Red Hat Red Hat Trusted Artifact Signer 1.4 unaffected 1775815407 * rpm Not specified
ADP Red Hat OpenShift Lightspeed Not specified Not specified
ADP Red Hat OpenShift Lightspeed Not specified Not specified
ADP Red Hat OpenShift Lightspeed Not specified Not specified
ADP Red Hat Red Hat AI Inference Server Not specified Not specified
ADP Red Hat Red Hat AI Inference Server Not specified Not specified
ADP Red Hat Red Hat Ansible Automation Platform 2 Not specified Not specified
ADP Red Hat Red Hat Ansible Automation Platform 2 Not specified Not specified
ADP Red Hat Red Hat Ansible Automation Platform 2 Not specified Not specified
ADP Red Hat Red Hat Ansible Automation Platform 2 Not specified Not specified
ADP Red Hat Red Hat Ansible Automation Platform 2 Not specified Not specified
ADP Red Hat Red Hat Ansible Automation Platform 2 Not specified Not specified
ADP Red Hat Red Hat Ansible Automation Platform 2 Not specified Not specified
ADP Red Hat Red Hat OpenShift AI RHOAI Not specified Not specified
ADP Red Hat Red Hat OpenShift AI RHOAI Not specified Not specified
ADP Red Hat Red Hat OpenShift AI RHOAI Not specified Not specified
ADP Red Hat Red Hat OpenShift AI RHOAI Not specified Not specified
ADP Red Hat Red Hat OpenShift AI RHOAI Not specified Not specified
ADP Red Hat Red Hat OpenShift AI RHOAI Not specified Not specified
ADP Red Hat Red Hat OpenShift AI RHOAI Not specified Not specified
ADP Red Hat Red Hat OpenShift AI RHOAI Not specified Not specified
ADP Red Hat Red Hat OpenShift AI RHOAI Not specified Not specified
ADP Red Hat Red Hat OpenShift AI RHOAI Not specified Not specified
ADP Red Hat Red Hat Satellite 6 Not specified Not specified
ADP Red Hat Red Hat Trusted Artifact Signer Not specified Not specified

References

ReferenceSourceLinkTags
access.redhat.com/errata/RHSA-2026:17083 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:13512 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:8437 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:13916 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:19355 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/security/cve/CVE-2026-32597 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:13553 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:21431 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:24977 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
github.com/jpadilla/pyjwt/security/advisories/GHSA-752w-5fwx-jx9f 134c704f-9b21-4f2e-91b3-4a467353bcc0 github.com Exploit, Mitigation, Vendor Advisory
access.redhat.com/errata/RHSA-2026:42644 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:6720 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:13508 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:8747 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:6568 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:10184 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:10140 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:37275 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32597.json 0b0ca135-0b70-47e7-9f44-1890c2a1c46c security.access.redhat.com
access.redhat.com/errata/RHSA-2026:21517 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:19375 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
lists.debian.org/debian-lts-announce/2026/05/msg00008.html af854a3a-2127-422b-91ae-364da2661108 lists.debian.org
access.redhat.com/errata/RHSA-2026:12176 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:10141 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:6912 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
bugzilla.redhat.com/show_bug.cgi 0b0ca135-0b70-47e7-9f44-1890c2a1c46c bugzilla.redhat.com
access.redhat.com/errata/RHSA-2026:6926 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:8746 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:8748 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:13672 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:19138 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:26226 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:13545 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:19712 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
access.redhat.com/errata/RHSA-2026:22330 0b0ca135-0b70-47e7-9f44-1890c2a1c46c access.redhat.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Additional Advisory Data

SourceTimeEvent
ADP2026-03-12T22:01:29.967ZReported to Red Hat.
ADP2026-03-12T21:41:50.427ZMade public.

Solutions

ADP: RHSA-2026:13512: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9

ADP: RHSA-2026:13508: Red Hat Ansible Automation Platform 2.6 for RHEL 9

ADP: RHSA-2026:17083: Red Hat Enterprise Linux AppStream EUS (v. 10.0)

ADP: RHSA-2026:13916: Red Hat Enterprise Linux AppStream (v. 10)

ADP: RHSA-2026:19138: Red Hat Enterprise Linux AppStream (v. 10)

ADP: RHSA-2026:12176: Red Hat Enterprise Linux AppStream (v. 8), Red Hat Enterprise Linux HighAvailability (v. 8), Red Hat Enterprise Linux ResilientStorage (v. 8)

ADP: RHSA-2026:22330: Red Hat Enterprise Linux AppStream E4S (v.9.2), Red Hat Enterprise Linux High Availability E4S (v.9.2), Red Hat Enterprise Linux Resilient Storage E4S (v.9.2)

ADP: RHSA-2026:21517: Red Hat Enterprise Linux AppStream EUS (v.9.4), Red Hat Enterprise Linux High Availability EUS (v.9.4), Red Hat Enterprise Linux Resilient Storage EUS (v.9.4)

ADP: RHSA-2026:21431: Red Hat Enterprise Linux AppStream EUS (v.9.6)

ADP: RHSA-2026:13672: Red Hat Enterprise Linux AppStream (v. 9)

ADP: RHSA-2026:19355: Red Hat Enterprise Linux AppStream (v. 9)

ADP: RHSA-2026:8748: Red Hat AI Inference Server 3.3

ADP: RHSA-2026:8746: Red Hat AI Inference Server 3.3

ADP: RHSA-2026:8747: Red Hat AI Inference Server 3.3

ADP: RHSA-2026:13553: Red Hat Ansible Automation Platform 2.5

ADP: RHSA-2026:13545: Red Hat Ansible Automation Platform 2.6

ADP: RHSA-2026:10140: Red Hat Enterprise Linux AI 3.3

ADP: RHSA-2026:10141: Red Hat Enterprise Linux AI 3.3

ADP: RHSA-2026:10184: Red Hat OpenShift AI 2.25

ADP: RHSA-2026:42644: Red Hat OpenShift AI 2.25

ADP: RHSA-2026:24977: Red Hat OpenShift AI 2.25

ADP: RHSA-2026:37275: Red Hat OpenShift AI 3.3

ADP: RHSA-2026:19712: Red Hat OpenShift AI 3.3

ADP: RHSA-2026:6720: Red Hat Quay 3.12

ADP: RHSA-2026:6568: Red Hat Quay 3.15

ADP: RHSA-2026:19375: Red Hat Quay 3.16

ADP: RHSA-2026:6912: Red Hat Quay 3.1

ADP: RHSA-2026:6926: Red Hat Quay 3.9

ADP: RHSA-2026:26226: Red Hat Satellite 6.18

ADP: RHSA-2026:8437: Red Hat Trusted Artifact Signer 1.4

Workarounds

ADP: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report