{"id":"CVE-2026-96760","title":"Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability","summary":"Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking f…","severity":"none","cwe":["CWE-347","CWE-670","CWE-358","CWE-20"],"vendor":"Authlib","product":"Authlib","affected":["Authlib 1.7.2"],"published":"2026-09-28","updated":"2026-09-28","sourceUpdated":"2026-09-28T21:17:19.650","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-96760","references":[{"url":"https://github.com/authlib/authlib","label":"cret@cert.org"},{"url":"https://kb.cert.org/vuls/id/762428","label":"cret@cert.org"},{"url":"https://www.kb.cert.org/vuls/id/762428","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-28T20:20:05.662Z","slug":"CVE-2026-96760","body":"## Overview\n\nAuthlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}