AI description
CVE-2026-27962 describes a JWK (JSON Web Key) Header Injection vulnerability found in Authlib, a Python library used for authentication and authorization systems. This flaw specifically impacts how Authlib verifies digital signatures within JWS (JSON Web Signature) tokens. The vulnerability arises when `key=None` is passed to a JWS deserialization function, or when a key resolver callable returns `None` for unknown or rotated `kid` (key ID) values. An attacker can exploit this by crafting a special JWT (JSON Web Token) that includes their own cryptographic public key within the `jwk` header field. By signing the token with their corresponding private key, the system, attempting to verify the token without a predefined key, mistakenly uses the attacker's embedded key. This allows the forged token to pass signature verification, effectively bypassing authentication and authorization mechanisms. The issue has been patched in Authlib version 1.6.9.
- Description
- Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrary JWT tokens that pass signature verification. When key=None is passed to any JWS deserialization function, the library extracts and uses the cryptographic key embedded in the attacker-controlled JWT jwk header field. An attacker can sign a token with their own private key, embed the matching public key in the header, and have the server accept the forged token as cryptographically valid ā bypassing authentication and authorization entirely. This issue has been patched in version 1.6.9.
- Source
- security-advisories@github.com
- NVD status
- Modified
- Products
- authlib
CVSS 3.1
- Type
- Secondary
- Base score
- 9.1
- Impact score
- 5.2
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity
- CRITICAL
- Hype score
- Not currently trending
šØ SECURITY ALERT: Multiple Authlib signature-verification flaws can allow forged JWS/JWT payloads to bypass cryptographic validation. ⢠CVE-2026-96760 ā Authlib ⤠1.7.2 ⢠CVE-2026-27962 ā fixed in 1.6.9 ⢠CVE-2026-28802 ā fixed in 1.6.7 The flaws can undermine
@ThreatWire_
29 Sept 2026
752 Impressions
1 Retweet
10 Likes
5 Bookmarks
0 Replies
0 Quotes
An Authlib signature bypass vulnerability (CVE-2026-96760, CVE-2026-28802, CVE-2026-27962) lets attackers forge JWS payloads. Update libraries now. #Authlib #CVE202696760 #Cybersecurity #JWS #Vulnerability https://t.co/YEXnUBVXjQ
@Daily_CyberSec
29 Sept 2026
405 Impressions
1 Retweet
1 Like
3 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:authlib:authlib:*:*:*:*:*:*:*:*",
"matchCriteriaId": "8C677FEC-2094-49D8-ABAB-F740B6F83D38",
"versionEndExcluding": "1.6.9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]