CVE-2026-96760

Published Sep 28, 2026

Last updated 4 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-96760 describes a signature verification bypass vulnerability found in Authlib, specifically in versions 1.7.2 and below. This flaw resides within the `JsonWebSignature.deserialize_json()` method. The vulnerability allows an attacker to bypass digital signature verification when processing JSON Web Signature (JWS) objects. The `deserialize_json()` function incorrectly marks payloads as successfully verified without validating cryptographic signatures or requiring a verification key. This means that manipulated data can be treated as authentic and trusted by an application, potentially leading to unauthorized access or other security compromises.

Description
Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key.
Source
cret@cert.org
NVD status
Awaiting Analysis

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

3