Improper verification of cryptographic signature in authlib - CVE-2026-96760
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to forge arbitrary authenticated payloads.
The vulnerability exists due to improper verification of cryptographic signatures in the Authlib JsonWebSignature.deserialize_json() function when processing JWS general JSON serialization objects. A remote attacker can submit a JWS object with an empty signatures array to forge arbitrary authenticated payloads.