Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Nguyen Minh Tuan

#27332of 57,303
9.8Total CVSS
Vulnerabilities · 1
PT-2026-102339
9.8
2026-09-28
Pypi · Oauthlib · CVE-2026-96760
**Name of the Vulnerable Software and Affected Versions** Authlib versions prior to 1.7.3 **Description** An issue exists in the JWS general JSON serialization handler where the `JsonWebSignature.deserialize json()` function accepts a JWS object with an empty `signatures` array and treats the payload as successfully verified. This allows an attacker to supply arbitrary forged content, such as tokens or assertions, without requiring a cryptographic key or possessing signing key material. **Recommendations** Update to Authlib version 1.7.3 or later. Implement a compensating control at the reverse proxy or API gateway layer to reject any JWS object where the `signatures` array is empty or missing before it reaches the application logic.