AI description
CVE-2026-28802 describes a signature verification bypass vulnerability found in Authlib, a Python library used for building OAuth and OpenID Connect servers. This flaw affects Authlib versions 1.6.5 through 1.6.6. The vulnerability allows a remote attacker to craft a malicious JSON Web Token (JWT) by specifying the "alg: none" algorithm in the header and providing an empty signature. This crafted token can then bypass the expected signature verification process in applications utilizing the affected Authlib versions, potentially leading to unauthorized access or actions. The issue has been addressed in Authlib version 1.6.7.
- Description
- Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature verification step without any changes to the application code when a failure was expected.. This issue has been patched in version 1.6.7.
- Source
- security-advisories@github.com
- NVD status
- Modified
- Products
- authlib
CVSS 4.0
- Type
- Secondary
- Base score
- 7.7
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
3
šØ SECURITY ALERT: Multiple Authlib signature-verification flaws can allow forged JWS/JWT payloads to bypass cryptographic validation. ⢠CVE-2026-96760 ā Authlib ⤠1.7.2 ⢠CVE-2026-27962 ā fixed in 1.6.9 ⢠CVE-2026-28802 ā fixed in 1.6.7 The flaws can undermine
@ThreatWire_
29 Sept 2026
752 Impressions
1 Retweet
10 Likes
5 Bookmarks
0 Replies
0 Quotes
An Authlib signature bypass vulnerability (CVE-2026-96760, CVE-2026-28802, CVE-2026-27962) lets attackers forge JWS payloads. Update libraries now. #Authlib #CVE202696760 #Cybersecurity #JWS #Vulnerability https://t.co/YEXnUBVXjQ
@Daily_CyberSec
29 Sept 2026
405 Impressions
1 Retweet
1 Like
3 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:authlib:authlib:*:*:*:*:*:*:*:*",
"matchCriteriaId": "1DBAF459-BB6F-4AF1-935B-D9A8D40C643A",
"versionEndExcluding": "1.6.7",
"versionStartIncluding": "1.6.5",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]