CVE-2026-75509
joserfc claim-validation bypass via array-typed single-string claims (iss/sub/jti)
CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th
joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to version 1.7.3, JWTClaimsRegistry applies membership matching to list-valued iss and sub claims, allowing an array-valued iss that contains the expected issuer to pass an intended equality check and enabling issuer-validation bypass. This issue is fixed in version 1.7.3.
| CWE | CWE-290 CWE-345 |
| Vendor | authlib |
| Product | joserfc |
| Published | Aug 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for authlib joserfc
Be the first to know when new medium vulnerabilities affecting authlib joserfc are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
None
Affected Versions
authlib / joserfc
< 1.7.3