VU#762428: Authlib library contains a signature‑verification bypass vulnerability

CERT Coordination Center Version 1 original current

Imported from official source

Authlib (versions up to and including 1.7.2) contain a signature‑verification bypass in the JSON Web Signature (JWS) general JSON serialization handling. The JsonWebSignature.deserialize_json() function accepts a JWS object with an empty "signatures" array and treats the payload as successfully verified, allowing attackers to supply arbitrary forged content without possessing any key material. …

This version

Version
1 of 1
Recorded
September 28, 2026 20:00
Change
Initial
Content hash
a72c535b7370ba22e740b363ce0ebaa2
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.