CVE-2026-75509
6.5
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N
Summary
joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership matching to list-valued iss and sub claims, allowing an array-valued iss that contains the expected issuer to pass an intended equality check and enabling issuer-validation bypass. This issue is fixed in version 1.7.3.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| authlib | joserfc | < 1.7.3 | affected |
Weaknesses
- CWE-290: CWE-290: Authentication Bypass by Spoofing
- CWE-345: CWE-345: Insufficient Verification of Data Authenticity
References
- https://github.com/authlib/joserfc/security/advisories/GHSA-r74j-q665-7rpj
- https://github.com/authlib/joserfc/commit/76ee6a59bf5773c0af00b99076c5e199031f97f1
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.