CVE-2026-28802
Authlib none algorithm accepted on 1.6.5 and 1.6.6
Authlib 1.6.5 and 1.6.6 can accept a JWT that uses the none algorithm and an empty signature. Fixed in 1.6.7. NVD’s CVSS 4.0 score is 7.7.
- CVSS
- 7.7
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
- Class
- Auth bypass
- Status
- No PoC
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- Authlib
- Products
- Authlib
- Affected
- 1.6.5 and 1.6.6.
- Fixed
- 1.6.7
- CWE
- CWE-347
- Published
- 6 Mar 2026
- Updated
- 5 Oct 2026
No public PoC is confirmed on this record.
CVE-2026-28802 affects Authlib 1.6.5 and 1.6.6. GitHub advisory GHSA-7wc2-qxgw-g8gg, published 4 March 2026, says a JWT that uses the none algorithm and an empty signature can pass verification on those versions. NVD’s CVSS 4.0 score is 7.7. The high impact in that vector is integrity. Confidentiality and availability on the vulnerable system are none.
The patch release is 1.6.7. Versions before 1.6.5 are outside the range in the advisory. CISA has not listed the CVE. This is not CVE-2026-27962 and not CVE-2026-96760.