Microsoft Security Response Center guidance
Release Notes
Vulnerability intelligence
CVE-2026-102265 and is rated Medium severity with a CVSS score of 5.3. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Release Notes
PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWS._load in jwt/api_jws.py is affected because parser catches ValueError but not RecursionError. This occurs when a deeply nested token header reaches json.loads. As a result, RecursionError escapes the documented PyJWT error hierarchy. Consequently, an unauthenticated malformed token can cause a request-level failure and HTTP 500. This issue is fixed in version 2.14.0.