MEDIUM SEVERITYCONFIRMED
3-byte HMAC key accepted — enforce_minimum_key_length defaults to False
Package
PyJWT
Version
2.11.0
Verified
2026-03-28
Description
PyJWT accepts a 3-byte key for HS256 with only an `InsecureKeyLengthWarning`. The `enforce_minimum_key_length` option (added in 2.9.0) defaults to `False`, meaning sub-minimum keys do not raise an error unless explicitly configured. RFC 7518 Section 3.2 requires 32 bytes for SHA-256.
Reproduction
import jwt, warnings
with warnings.catch_warnings(record=True) as w:
warnings.simplefilter('always')
token = jwt.encode({'sub': 'admin'}, 'abc', algorithm='HS256')
result = jwt.decode(token, 'abc', algorithms=['HS256'])
# result = {'sub': 'admin'} — weak key accepted