Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-96760: Authlib library can accept unsigned data as verified

CVE-2026-96760 · published 12 days ago
Summary

The Authlib software (versions up to 1.7.2) may treat data as securely signed even when no signature is present. This lets an attacker create fake authentication tokens that the system will trust. Update Authlib to a newer version or apply the vendor's patch to restore proper signature checking.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
Ecosystem VendorProductAffected versions
– authlib authlib 1.7.2
Ubuntu:Pro:22.04:LTS canonical python-authlib All versions
Debian:12 debian python-authlib All versions
Original advisory text
Authlib library contains a signature‑verification bypass vulnerability
Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-347Improper Verification of Cryptographic Signature
CWE-670Always-Incorrect Control Flow Implementation
CWE-358Improperly Implemented Security Check for Standard
CWE-20Improper Input Validation
Timeline
Published28 Sep 2026
Updated9 Oct 2026
First seen28 Sep 2026
Track software like this
Free during beta