Pypi · Oauthlib · CVE-2026-96760
**Name of the Vulnerable Software and Affected Versions**
Authlib versions prior to 1.7.3
**Description**
An issue exists in the JWS general JSON serialization handler where the `JsonWebSignature.deserialize json()` function accepts a JWS object with an empty `signatures` array and treats the payload as successfully verified. This allows an attacker to supply arbitrary forged content, such as tokens or assertions, without requiring a cryptographic key or possessing signing key material.
**Recommendations**
Update to Authlib version 1.7.3 or later.
Implement a compensating control at the reverse proxy or API gateway layer to reject any JWS object where the `signatures` array is empty or missing before it reaches the application logic.