CVE-2026-32597: PyJWT Flaw Can Silently Bypass Token Validation
A newly disclosed PyJWT vulnerability (CVE-2026-32597) fails to reject tokens with unrecognized 'crit' header values, opening an authentication-bypass path for affected apps.
News, tech and practical guides
A newly disclosed PyJWT vulnerability (CVE-2026-32597) fails to reject tokens with unrecognized 'crit' header values, opening an authentication-bypass path for affected apps.