PT-2026-23089 · Pypi+1 · Oauthlib+1
Michael-Guignard
·
Published
2026-03-04
·
Updated
2026-05-21
·
CVE-2026-28802
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Authlib versions 1.6.5 through 1.6.7
Description
Authlib, a Python library for building OAuth and OpenID Connect servers, had a flaw in signature verification. Specifically, tests involving a malicious JWT with 'alg: none' and an empty signature were incorrectly passing verification without any code changes when a failure was expected. This issue was introduced in a commit that altered signature verification logic. Exploitation of this issue could allow attackers to bypass authentication, escalate privileges, gain unauthorized access, or modify application data by submitting forged JWTs. The issue was addressed in version 1.6.7.
Recommendations
Authlib versions 1.6.5 through 1.6.7 should be updated to version 1.6.7 or later.
Exploit
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oauthlib
Red Os