Skip to content
THREATWIRE

CVE

CriticalNo PoC

CVE-2026-96760

Authlib JSON signature list treated as verified

Authlib through 1.7.2 can treat a JSON Web Signature with an empty signatures list as verified. CERT/CC published the note on 28 September 2026. No finished release that closes it was found.

CVSS
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Class
Auth bypass
Status
No PoC
KEV
Not in CISA KEV
0-day
No
Vendor
Authlib
Products
Authlib
Affected
1.7.2 and earlier, for JsonWebSignature.deserialize_json().
Fixed
No released fix found. Pull request 938 on authlib/authlib was still open.
Published
28 Sept 2026
Updated
5 Oct 2026

No public PoC is confirmed on this record.

CVE-2026-96760 is a signature-verification bypass in Authlib’s JSON serialization of a JSON Web Signature. NVD and CERT/CC VU#762428 say JsonWebSignature.deserialize_json() can return a payload as verified when the signatures list is empty, without a cryptographic key. NVD scores it 9.8.

The affected range in those sources is 1.7.2 and earlier. CERT/CC first published the note on 28 September 2026. CISA has not listed the CVE. An Authlib pull request that describes a fix for empty-signature validation was still open, so this record does not name a released fixed version. Installing 1.6.9, which closes a different Authlib bug, does not close this one.

Sources

Related writing

Share on X@threatwire_https://www.threatwire.tech/cve/cve-2026-96760