Skip to content
THREATWIRE

CVE

HighNo PoC

CVE-2026-28802

Authlib none algorithm accepted on 1.6.5 and 1.6.6

Authlib 1.6.5 and 1.6.6 can accept a JWT that uses the none algorithm and an empty signature. Fixed in 1.6.7. NVD’s CVSS 4.0 score is 7.7.

CVSS
7.7
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Class
Auth bypass
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
Authlib
Products
Authlib
Affected
1.6.5 and 1.6.6.
Fixed
1.6.7
Published
6 Mar 2026
Updated
5 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-28802 affects Authlib 1.6.5 and 1.6.6. GitHub advisory GHSA-7wc2-qxgw-g8gg, published 4 March 2026, says a JWT that uses the none algorithm and an empty signature can pass verification on those versions. NVD’s CVSS 4.0 score is 7.7. The high impact in that vector is integrity. Confidentiality and availability on the vulnerable system are none.

The patch release is 1.6.7. Versions before 1.6.5 are outside the range in the advisory. CISA has not listed the CVE. This is not CVE-2026-27962 and not CVE-2026-96760.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-28802