CVE-2026-27962

Published Mar 16, 2026

Last updated 22 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-27962 describes a JWK (JSON Web Key) Header Injection vulnerability found in Authlib, a Python library used for authentication and authorization systems. This flaw specifically impacts how Authlib verifies digital signatures within JWS (JSON Web Signature) tokens. The vulnerability arises when `key=None` is passed to a JWS deserialization function, or when a key resolver callable returns `None` for unknown or rotated `kid` (key ID) values. An attacker can exploit this by crafting a special JWT (JSON Web Token) that includes their own cryptographic public key within the `jwk` header field. By signing the token with their corresponding private key, the system, attempting to verify the token without a predefined key, mistakenly uses the attacker's embedded key. This allows the forged token to pass signature verification, effectively bypassing authentication and authorization mechanisms. The issue has been patched in Authlib version 1.6.9.

Description
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrary JWT tokens that pass signature verification. When key=None is passed to any JWS deserialization function, the library extracts and uses the cryptographic key embedded in the attacker-controlled JWT jwk header field. An attacker can sign a token with their own private key, embed the matching public key in the header, and have the server accept the forged token as cryptographically valid — bypassing authentication and authorization entirely. This issue has been patched in version 1.6.9.
Source
security-advisories@github.com
NVD status
Modified
Products
authlib

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.1
Impact score
5.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity
CRITICAL

Weaknesses

security-advisories@github.com
CWE-347
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
CWE-347

Social media

Hype score
Not currently trending

Configurations