TL;DR
Running Infra, AppSec, and SOC teams? Tag CVE alerts by team automatically.
Try Team free for 14 daysCERT/CC released an advisory warning of an Authlib signature bypass vulnerability tracked as CVE-2026-96760. This flaw allows attackers to forge JSON Web Signatures (JWS) and inject malicious payloads without any key material. Developers must monitor for patches since the vendor has not released an official fix.
Why It Matters
Authlib is a widely used Python library for building OAuth, OpenID Connect, and JWT/JWS communication standards. This Authlib signature bypass vulnerability exposes microservices and web applications to severe authorization risks. Related identifiers like CVE-2026-28802 and CVE-2026-27962 highlight the importance of proper cryptographic validation in modern web frameworks. According to the advisory, systems relying on Authlib verification “may accept attacker-supplied content as legitimate”. A successful exploit could lead to forged privilege-escalation claims, compromised microservice messaging, and complete integrity bypass.
How The Attack Works
The defect exists in the library’s JWS general JSON serialization handling. The `deserialize_json()` function mistakenly accepts JWS objects that contain an empty “signatures” array. The function begins by assuming signatures are valid. It then skips verification entirely if the array is empty. Consequently, it treats unsigned data as properly signed. As CERT/CC details, “An attacker can forge arbitrary authenticated payloads without any signing key or credentials”. The attacker simply supplies a crafted JWS with no signatures. The vulnerable function then automatically trusts the malicious payload.
Affected Versions
This severe flaw affects Authlib versions up to and including 1.7.2. Both the `jws.deserialize_json()` and `jws.deserialize()` loading methods are vulnerable to this exploit.
Patch Or Mitigation Steps
Currently, no official patch is available because coordinators could not reach the vendor. Users are strongly advised to monitor the Authlib GitHub repository for new releases. You should update your libraries immediately once a fix becomes available.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!