Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 |
Mon, 28 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 28 Sep 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Authlib
Authlib authlib |
|
| Vendors & Products |
Authlib
Authlib authlib |
Mon, 28 Sep 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key. | |
| Title | Authlib library contains a signature‑verification bypass vulnerability | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-09-28T20:07:57.835Z
Reserved: 2026-09-23T15:59:27.145Z
Link: CVE-2026-96760
No data.
Status : Received
Published: 2026-09-28T20:17:11.703
Modified: 2026-09-28T21:17:19.650
Link: CVE-2026-96760
No data.
OpenCVE Enrichment
Updated: 2026-09-28T21:30:07Z
-
CWE-287
Improper Authentication