PT-2026-23089 · Pypi+1 · Oauthlib+1

Michael-Guignard

·

Published

2026-03-04

·

Updated

2026-05-21

·

CVE-2026-28802

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Authlib versions 1.6.5 through 1.6.7
Description Authlib, a Python library for building OAuth and OpenID Connect servers, had a flaw in signature verification. Specifically, tests involving a malicious JWT with 'alg: none' and an empty signature were incorrectly passing verification without any code changes when a failure was expected. This issue was introduced in a commit that altered signature verification logic. Exploitation of this issue could allow attackers to bypass authentication, escalate privileges, gain unauthorized access, or modify application data by submitting forged JWTs. The issue was addressed in version 1.6.7.
Recommendations Authlib versions 1.6.5 through 1.6.7 should be updated to version 1.6.7 or later.

Exploit

Fix

Improper Verification of Cryptographic Signature

Weakness Enumeration

Related Identifiers

BDU:2026-04355
CVE-2026-28802
ECHO-579F-8639-173E
GHSA-7WC2-QXGW-G8GG

Affected Products

Oauthlib
Red Os