Signature Verification Bypass in Authlib by Authlib
CVE-2026-96760

Currently unrated

Key Information:

Vendor

Authlib

Status
Vendor
CVE Published:
28 September 2026

What is CVE-2026-96760?

Authlib versions 1.7.2 and earlier have a vulnerability in the JsonWebSignature.deserialize_json() method, which improperly validates signatures. This flaw allows for the potential bypass of signature checks, as it accepts a JSON Serialization JWS object and returns the payload as verified, without requiring a cryptographic key. This presents a significant risk, enabling unauthorized access or manipulation of sensitive data.

Affected Version(s)

Authlib 1.7.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.