The vulnerability, CVE-2026-102268, stems from an incomplete guard against algorithm confusion in PyJWT. Specifically, the HMACAlgorithm.prepare_key function, which is responsible for preparing keys for HMAC operations, contains a security check that attempts to prevent asymmetric keys from being used as HMAC secrets. This check relies on the is_pem_format utility function to identify if a given key is in PEM format (indicating it might be an asymmetric key).
The core issue was that the is_pem_format function, located in jwt/utils.py, used a regular expression (_PEM_RE) that was too strict. This regex failed to recognize certain valid PEM formats that cryptography.load_pem_public_key() would still accept. These 'loader-accepted but regex-missed' PEM keys included those with marker-adjacent whitespace, CR-only line terminators, or keys folded onto a single line.
When such a malformed (from is_pem_format's perspective) but valid (from cryptography's perspective) asymmetric public key was provided, is_pem_format would return False. Consequently, the guard in HMACAlgorithm.prepare_key would not trigger an InvalidKeyError. Instead, the function would return the public key bytes, which would then be used as the secret for an HMAC algorithm (e.g., HS256). This allowed an attacker to forge tokens if the jwt.decode allow-list included both an HMAC and an asymmetric algorithm.
The patch addresses this by completely rewriting is_pem_format to use a more robust parsing logic that correctly identifies PEM markers, regardless of minor formatting variations, thus ensuring the HMACAlgorithm.prepare_key guard functions as intended.