PT-2026-102339 · Pypi · Oauthlib

·

CVE-2026-96760

·

Published

2026-09-28

·

Updated

2026-09-29

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Authlib versions prior to 1.7.3
Description An issue exists in the JWS general JSON serialization handler where the JsonWebSignature.deserialize json() function accepts a JWS object with an empty signatures array and treats the payload as successfully verified. This allows an attacker to supply arbitrary forged content, such as tokens or assertions, without requiring a cryptographic key or possessing signing key material.
Recommendations Update to Authlib version 1.7.3 or later. Implement a compensating control at the reverse proxy or API gateway layer to reject any JWS object where the signatures array is empty or missing before it reaches the application logic.

Fix

Improperly Implemented Security Check for Standard

RCE

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96760

Affected Products

Oauthlib