HIGH SEVERITYCONFIRMEDCVE-2024-33663

jwt.decode(algorithms=None) skips algorithm allowlist entirely

Package
python-jose
Version
3.5.0
Verified
2026-03-28

Description

In `jose/jws.py`, the algorithm check is `if algorithms is not None and alg not in algorithms`. Passing `algorithms=None` skips the check entirely — any algorithm is accepted. This is related to CVE-2024-33663/CVE-2024-33664 and remains unfixed in 3.5.0.

Reproduction

from jose import jwt
token = jwt.encode({'sub': 'admin', 'admin': True}, 'secret', algorithm='HS256')
result = jwt.decode(token, 'secret', algorithms=None)
# Returns: {'sub': 'admin', 'admin': True} — no algorithm restriction
← All bugsScan your code →