CVE-2026-28802

Published Mar 6, 2026

Last updated 20 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-28802 describes a signature verification bypass vulnerability found in Authlib, a Python library used for building OAuth and OpenID Connect servers. This flaw affects Authlib versions 1.6.5 through 1.6.6. The vulnerability allows a remote attacker to craft a malicious JSON Web Token (JWT) by specifying the "alg: none" algorithm in the header and providing an empty signature. This crafted token can then bypass the expected signature verification process in applications utilizing the affected Authlib versions, potentially leading to unauthorized access or actions. The issue has been addressed in Authlib version 1.6.7.

Description
Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature verification step without any changes to the application code when a failure was expected.. This issue has been patched in version 1.6.7.
Source
security-advisories@github.com
NVD status
Modified
Products
authlib

Risk scores

CVSS 4.0

Type
Secondary
Base score
7.7
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security-advisories@github.com
CWE-347
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
CWE-347

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

3

Configurations