🔐 CVE Alert

CVE-2026-96760

UNKNOWN 0.0

Authlib library contains a signature‑verification bypass vulnerability

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key.

Vendor authlib
Product authlib
Published Sep 28, 2026
Last Updated Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for authlib authlib

Be the first to know when new unknown vulnerabilities affecting authlib authlib are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Authlib / Authlib
1.7.2

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/authlib/authlib kb.cert.org: https://kb.cert.org/vuls/id/762428 kb.cert.org: https://www.kb.cert.org/vuls/id/762428