CVE-2026-96760
N/A
N/A
Summary
Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Authlib | Authlib | 1.7.2 | affected |
Weaknesses
- CWE-347 Improper Verification of Cryptographic Signature
- CWE-670 Always-Incorrect Control Flow Implementation
- CWE-358 Improperly Implemented Security Check for Standard
- CWE-20 Improper Input Validation
ADP Enrichment
CVE Program Container
Additional References
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.