CVE-2026-96760
Published Sep 28, 2026
Last updated 4 hours ago
AI description
CVE-2026-96760 describes a signature verification bypass vulnerability found in Authlib, specifically in versions 1.7.2 and below. This flaw resides within the `JsonWebSignature.deserialize_json()` method. The vulnerability allows an attacker to bypass digital signature verification when processing JSON Web Signature (JWS) objects. The `deserialize_json()` function incorrectly marks payloads as successfully verified without validating cryptographic signatures or requiring a verification key. This means that manipulated data can be treated as authentic and trusted by an application, potentially leading to unauthorized access or other security compromises.
- Description
- Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key.
- Source
- cret@cert.org
- NVD status
- Awaiting Analysis
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
3
šØ SECURITY ALERT: Multiple Authlib signature-verification flaws can allow forged JWS/JWT payloads to bypass cryptographic validation. ⢠CVE-2026-96760 ā Authlib ⤠1.7.2 ⢠CVE-2026-27962 ā fixed in 1.6.9 ⢠CVE-2026-28802 ā fixed in 1.6.7 The flaws can undermine
@ThreatWire_
29 Sept 2026
752 Impressions
1 Retweet
10 Likes
5 Bookmarks
0 Replies
0 Quotes
An Authlib signature bypass vulnerability (CVE-2026-96760, CVE-2026-28802, CVE-2026-27962) lets attackers forge JWS payloads. Update libraries now. #Authlib #CVE202696760 #Cybersecurity #JWS #Vulnerability https://t.co/YEXnUBVXjQ
@Daily_CyberSec
29 Sept 2026
405 Impressions
1 Retweet
1 Like
3 Bookmarks
0 Replies
0 Quotes