PT-2026-102339 · Pypi · Oauthlib
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Authlib versions prior to 1.7.3
Description
An issue exists in the JWS general JSON serialization handler where the
JsonWebSignature.deserialize json() function accepts a JWS object with an empty signatures array and treats the payload as successfully verified. This allows an attacker to supply arbitrary forged content, such as tokens or assertions, without requiring a cryptographic key or possessing signing key material.Recommendations
Update to Authlib version 1.7.3 or later.
Implement a compensating control at the reverse proxy or API gateway layer to reject any JWS object where the
signatures array is empty or missing before it reaches the application logic.Fix
Improperly Implemented Security Check for Standard
RCE
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oauthlib