---
id: CVE-2026-96760
title: >-
  Authlib (v1.7.2 and below) contains a signature verification bypass
  vulnerability
summary: >-
  Authlib (v1.7.2 and below) contains a signature verification bypass
  vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON
  Serialization JWS object and returns the payload as successfully verified
  without checking f…
severity: none
cwe:
  - CWE-347
  - CWE-670
  - CWE-358
  - CWE-20
vendor: Authlib
product: Authlib
affected:
  - Authlib 1.7.2
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T21:17:19.650'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96760'
references:
  - url: 'https://github.com/authlib/authlib'
    label: cret@cert.org
  - url: 'https://kb.cert.org/vuls/id/762428'
    label: cret@cert.org
  - url: 'https://www.kb.cert.org/vuls/id/762428'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T20:20:05.662Z'
---

## Overview

Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
