CVE-2026-96760None▾ SunlitAuthlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking f…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-28802Critical· 9.8Authlib is a Python library which builds OAuth and OpenID Connect servers
CVE-2026-27962Critical· 9.1Authlib is a Python library which builds OAuth and OpenID Connect servers
CVE-2026-44681Medium· 6.1Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect
CVE-2026-41425Medium· 5.4Authlib: Cross-site request forging when using cache
CVE-2026-28490HighAuthlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle
CVE-2025-61920High· 7.5Authlib is vulnerable to Denial of Service via Oversized JOSE Segments