PyJWT <2.12.0 Crit Header Param Bypass JWS Validation Failure
CVE-2026-32597 Published on March 12, 2026

PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-32597 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. An automatable proof of concept (POC) exploit exists. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
NONE
Integrity Impact:
HIGH
Availability Impact:
NONE

Weakness Types

Insufficient Verification of Data Authenticity

The software does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

What is an AuthZ Vulnerability?

The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

CVE-2026-32597 has been classified to as an AuthZ vulnerability or weakness.

Improper Verification of Cryptographic Signature

The software does not verify, or incorrectly verifies, the cryptographic signature for data.


Products Associated with CVE-2026-32597

Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.

 
 
 
 
 
 
 
 
 
 
 
 
 
 

Affected Versions

jpadilla pyjwt: Red Hat Ansible Automation Platform 2.5 for RHEL 8: Red Hat Ansible Automation Platform 2.5 for RHEL 8: Red Hat Ansible Automation Platform 2.5 for RHEL 9: Red Hat Ansible Automation Platform 2.5 for RHEL 9: Red Hat Ansible Automation Platform 2.6 for RHEL 9: Red Hat Ansible Automation Platform 2.6 for RHEL 9: Red Hat Enterprise Linux 10: Red Hat Enterprise Linux 10.0 Extended Update Support: Red Hat Enterprise Linux 8: Red Hat Enterprise Linux 9: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions: Red Hat Enterprise Linux 9.4 Extended Update Support: Red Hat Enterprise Linux 9.6 Extended Update Support: Red Hat AI Inference Server 3.3: Red Hat AI Inference Server 3.3: Red Hat AI Inference Server 3.3: Red Hat Ansible Automation Platform 2.5: Red Hat Ansible Automation Platform 2.5: Red Hat Ansible Automation Platform 2.6: Red Hat Ansible Automation Platform 2.6: Red Hat Ansible Automation Platform 2.6: Red Hat Ansible Automation Platform 2.6: Red Hat Ansible Automation Platform 2.6: Red Hat Ansible Automation Platform 2.6: Red Hat Ansible Automation Platform 2.6: Red Hat Enterprise Linux AI 3.3: Red Hat Enterprise Linux AI 3.3: Red Hat Enterprise Linux AI 3.3: Red Hat Enterprise Linux AI 3.3: Red Hat Enterprise Linux AI 3.3: Red Hat Enterprise Linux AI 3.3: Red Hat Enterprise Linux AI 3.3: Red Hat OpenShift AI 2.25: Red Hat OpenShift AI 2.25: Red Hat OpenShift AI 2.25: Red Hat OpenShift AI 2.25: Red Hat OpenShift AI 2.25: Red Hat OpenShift AI 2.25: Red Hat OpenShift AI 2.25: Red Hat OpenShift AI 2.25: Red Hat OpenShift AI 2.25: Red Hat OpenShift AI 2.25: Red Hat OpenShift AI 2.25: Red Hat OpenShift AI 2.25: Red Hat OpenShift AI 2.25: Red Hat OpenShift AI 2.25: Red Hat OpenShift AI 2.25: Red Hat OpenShift AI 2.25: Red Hat OpenShift AI 3.3: Red Hat OpenShift AI 3.3: Red Hat OpenShift AI 3.3: Red Hat Quay 3.1: Red Hat Quay 3.12: Red Hat Quay 3.15: Red Hat Quay 3.16: Red Hat Quay 3.9: Red Hat Satellite 6.18: Red Hat Trusted Artifact Signer 1.4: Red Hat OpenShift Lightspeed: Red Hat OpenShift Lightspeed: Red Hat OpenShift Lightspeed: Red Hat AI Inference Server: Red Hat AI Inference Server: Red Hat Ansible Automation Platform 2: Red Hat Ansible Automation Platform 2: Red Hat Ansible Automation Platform 2: Red Hat Ansible Automation Platform 2: Red Hat Ansible Automation Platform 2: Red Hat Ansible Automation Platform 2: Red Hat Ansible Automation Platform 2: Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat OpenShift AI (RHOAI): Red Hat Satellite 6: Red Hat Trusted Artifact Signer:

Exploit Probability

EPSS
0.27%
Percentile
18.83%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.