Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-96760: Authlib library can accept unsigned data as verified
CVE-2026-96760 · published 12 days ago
Summary
The Authlib software (versions up to 1.7.2) may treat data as securely signed even when no signature is present. This lets an attacker create fake authentication tokens that the system will trust. Update Authlib to a newer version or apply the vendor's patch to restore proper signature checking.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | authlib | authlib | 1.7.2 |
| Ubuntu:Pro:22.04:LTS | canonical | python-authlib | All versions |
| Debian:12 | debian | python-authlib | All versions |
Original advisory text
Authlib library contains a signature‑verification bypass vulnerability
Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key.
References
- https://github.com/authlib/authlib
- https://kb.cert.org/vuls/id/762428
- https://www.kb.cert.org/vuls/id/762428
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/96xxx/CVE-2026-96760... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-96760 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-96760 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-96760 Third Party Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-96760 Vendor Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Severity
9.8
Critical
Type
CWE-347Improper Verification of Cryptographic Signature
CWE-670Always-Incorrect Control Flow Implementation
CWE-358Improperly Implemented Security Check for Standard
CWE-20Improper Input Validation
Timeline
Published28 Sep 2026
Updated9 Oct 2026
First seen28 Sep 2026
Sources
CVE-2026-96760 · NVD
CVE-2026-96760 · MITRE
CVE-2026-96760 · OSV
UBUNTU-CVE-2026-96760 · OSV
DEBIAN-CVE-2026-96760 · OSV
Track software like this
Free during beta