CVE-2026-101917
MediumAdvisory
Published 28 Sept 2026In the index since 30 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 5.3
- base score, highest
- EPSS
- 0.004
- 27th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 379
- of 17,957 indexed, latest versions
- Container images
- 377
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
PyJWT: PyJWKClient still amplifies unauthenticated JWKS fetches on unknown kid values (incomplete fix of CVE-2026-48524)
Carried by container images the latest versions of 379 of 17,957 indexed charts deploy, on 377 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| pyjwtpypi | 1.4.2, 1.5.3, 1.6.1, 1.6.4+17 more | 2.14.0 | 377 |
| pyjwtdeb | 1.7.1-2ubuntu2.1, 2.3.0-1, 2.3.0-1ubuntu0.2, 2.3.0-1ubuntu0.3+6 more | no fix listed | 39 |
- OSV records
- DEBIAN-CVE-2026-101917GHSA-2gx3-rcp4-g85qUBUNTU-CVE-2026-101917
- Trending
- Rank 49 in indexed charts, since 30 Sept 2026. See the ranking →
Charts affected
379 by stars
Container images carrying it
377 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| amundsendev/ | 69e7915e61c1 | pyjwt | 2.14.0 | 1 |
| andrcuns/ | 43060f159f4c | pyjwt pyjwt | no fix listed 2.14.0 | 1 |
| apache/ | 64e58748b6b9 | pyjwt | 2.14.0 | 1 |
| apache/ | ce90bdc3d2af | pyjwt | 2.14.0 | 1 |
| apache/ | e5560ad0b86e | pyjwt | 2.14.0 | 1 |
| apache/ | 75d48a62748f | pyjwt pyjwt | no fix listed 2.14.0 | 1 |
| apache/ | a2bab1be574c | pyjwt pyjwt | no fix listed 2.14.0 | 1 |
| apache/ | 975ab033580d | pyjwt | 2.14.0 | 1 |
| apache/ | ab9467fd712c | pyjwt | 2.14.0 | 1 |
| apache/ | 80072bb73dd3 | pyjwt pyjwt | no fix listed 2.14.0 | 1 |
| apache/ | ffab324253ed | pyjwt | 2.14.0 | 1 |
| apecloud/ | 8ac9947a2c84 | pyjwt | 2.14.0 | 1 |
| aristidetm/ | ccb516cb8474 | pyjwt | 2.14.0 | 1 |
| baserow/ | 7c00549b3a6f | pyjwt | 2.14.0 | 1 |
| baserow/ | e0b3c8130b91 | pyjwt | 2.14.0 | 1 |
| baserow/ | df0c42eb67e8 | pyjwt | 2.14.0 | 1 |
| bcgovimages/ | faa2e2d21916 | pyjwt | 2.14.0 | 1 |
| berkeleyskypilot/ | 3bc8bf8f4d83 | pyjwt | 2.14.0 | 1 |
| berkeleyskypilot/ | 8da2f3cda472 | pyjwt | 2.14.0 | 1 |
| bmeares/ | 8e9c5bacaa82 | pyjwt | 2.14.0 | 1 |
| boky/ | aafc77238423 | pyjwt | 2.14.0 | 1 |
| buntha/ | 154542cc3083 | pyjwt | 2.14.0 | 1 |
| burakince/ | ab4b566644b9 | pyjwt | 2.14.0 | 1 |
| camptocamp/ | ae874f70cc16 | pyjwt pyjwt | no fix listed 2.14.0 | 1 |
| cdignam/ | 5a6a55b39cee | pyjwt | 2.14.0 | 1 |
| ceph/ | 90f30824a96e | pyjwt | 2.14.0 | 1 |
| checkmk/ | c11b422210c4 | pyjwt | 2.14.0 | 1 |
| chiefonboarding/ | d0964135ea82 | pyjwt | 2.14.0 | 1 |
| ckan/ | 87ecf3f27ad6 | pyjwt | 2.14.0 | 1 |
| clowder/ | 11f3d844e4c0 | pyjwt | 2.14.0 | 1 |
| clowder/ | 14155326c7b9 | pyjwt | 2.14.0 | 1 |
| clowder/ | bf146f1ca24f | pyjwt | 2.14.0 | 1 |
| codecov/ | 0475cb1c3136 | pyjwt | 2.14.0 | 1 |
| codecov/ | 837f546b479b | pyjwt | 2.14.0 | 1 |
| dagster/ | e29285673c2c | pyjwt | 2.14.0 | 1 |
| datadog/ | 8f20e56b5311 | pyjwt | 2.14.0 | 1 |
| datadog/ | aad9994de6a7 | pyjwt | 2.14.0 | 1 |
| datamate/ | 2dd66b722464 | pyjwt pyjwt | no fix listed 2.14.0 | 1 |
| ddosify/ | a43c5155fa1c | pyjwt | 2.14.0 | 1 |
| ddosify/ | e5be48b37348 | pyjwt | 2.14.0 | 1 |
| ddosify/ | 3c11e3182652 | pyjwt | 2.14.0 | 1 |
| ddosify/ | ac323d52bfb4 | pyjwt | 2.14.0 | 1 |
| decisionrules/ | 557dea1373aa | pyjwt | 2.14.0 | 1 |
| defectdojo/ | 6516f0f62086 | pyjwt | 2.14.0 | 1 |
| devopshq/ | 30e093bffa91 | pyjwt | 2.14.0 | 1 |
| dpage/ | 18cd5711fc9a | pyjwt | 2.14.0 | 1 |
| dpage/ | 37946e4f3e7b | pyjwt | 2.14.0 | 1 |
| dpage/ | 50700ac17936 | pyjwt | 2.14.0 | 1 |
| dpage/ | 52cb72a9e3da | pyjwt | 2.14.0 | 1 |
| dpage/ | 561c1f8f99f2 | pyjwt | 2.14.0 | 1 |