PyJWT <2.12.0 Crit Header Param Bypass JWS Validation Failure
CVE-2026-32597 Published on March 12, 2026
PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)
PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting it. This violates the MUST requirement in the RFC. This vulnerability is fixed in 2.12.0.
Vulnerability Analysis
CVE-2026-32597 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. An automatable proof of concept (POC) exploit exists. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.
Weakness Types
Insufficient Verification of Data Authenticity
The software does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
What is an AuthZ Vulnerability?
The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVE-2026-32597 has been classified to as an AuthZ vulnerability or weakness.
Improper Verification of Cryptographic Signature
The software does not verify, or incorrectly verifies, the cryptographic signature for data.
Products Associated with CVE-2026-32597
Want to know whenever a new CVE is published for Red Hat products? stack.watch will email you.
Affected Versions
jpadilla pyjwt:- Version < 2.12.0 is affected.
- Version 0:4.6.28-3.el8ap and below * is unaffected.
- Version 0:2.12.1-1.el8ap and below * is unaffected.
- Version 0:4.6.28-3.el9ap and below * is unaffected.
- Version 0:2.12.1-1.el9ap and below * is unaffected.
- Version 0:4.7.11-2.el9ap and below * is unaffected.
- Version 0:2.12.1-1.el9ap and below * is unaffected.
- Version 0:4.16.0-13.el10_1.4 and below * is unaffected.
- Version 0:4.16.0-21.el10_2.1 and below * is unaffected.
- Version 0:4.16.0-5.el10_0.9 and below * is unaffected.
- Version 0:4.2.1-129.el8_10.25 and below * is unaffected.
- Version 0:4.10.0-110.el9_8.2 and below * is unaffected.
- Version 0:4.10.0-98.el9_7.12 and below * is unaffected.
- Version 0:4.10.0-43.el9_2.21 and below * is unaffected.
- Version 0:4.10.0-62.el9_4.24 and below * is unaffected.
- Version 0:4.10.0-86.el9_6.16 and below * is unaffected.
- Version 1775680192 and below * is unaffected.
- Version 1775680262 and below * is unaffected.
- Version 1775749857 and below * is unaffected.
- Version 1777394109 and below * is unaffected.
- Version 1777403872 and below * is unaffected.
- Version 1777296732 and below * is unaffected.
- Version 1777391447 and below * is unaffected.
- Version 1777311120 and below * is unaffected.
- Version 1777299023 and below * is unaffected.
- Version 1777398576 and below * is unaffected.
- Version 1777387242 and below * is unaffected.
- Version 1777311601 and below * is unaffected.
- Version 1776871984 and below * is unaffected.
- Version 1776871985 and below * is unaffected.
- Version 1776872005 and below * is unaffected.
- Version 1776773390 and below * is unaffected.
- Version 1776871987 and below * is unaffected.
- Version 1776773505 and below * is unaffected.
- Version 1776938871 and below * is unaffected.
- Version 1776338381 and below * is unaffected.
- Version 1776343111 and below * is unaffected.
- Version 1780069069 and below * is unaffected.
- Version 1783696512 and below * is unaffected.
- Version 1783616068 and below * is unaffected.
- Version 1783998551 and below * is unaffected.
- Version 1783664916 and below * is unaffected.
- Version 1783615385 and below * is unaffected.
- Version 1783664921 and below * is unaffected.
- Version 1783696507 and below * is unaffected.
- Version 1783615414 and below * is unaffected.
- Version 1783998585 and below * is unaffected.
- Version 1783664921 and below * is unaffected.
- Version 1783615165 and below * is unaffected.
- Version 1783664921 and below * is unaffected.
- Version 1783615432 and below * is unaffected.
- Version 1778264363 and below * is unaffected.
- Version 1778600187 and below * is unaffected.
- Version 1782472374 and below * is unaffected.
- Version 1775169155 and below * is unaffected.
- Version 1775253092 and below * is unaffected.
- Version 1775169219 and below * is unaffected.
- Version 1779204086 and below * is unaffected.
- Version 1775169218 and below * is unaffected.
- Version 1780414237 and below * is unaffected.
- Version 1775815407 and below * is unaffected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.