CVE-2026-96760
Authlib JSON signature list treated as verified
Authlib through 1.7.2 can treat a JSON Web Signature with an empty signatures list as verified. CERT/CC published the note on 28 September 2026. No finished release that closes it was found.
- CVSS
- 9.8
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Class
- Auth bypass
- Status
- No PoC
- KEV
- Not in CISA KEV
- 0-day
- No
- Vendor
- Authlib
- Products
- Authlib
- Affected
- 1.7.2 and earlier, for JsonWebSignature.deserialize_json().
- Fixed
- No released fix found. Pull request 938 on authlib/authlib was still open.
- CWE
- CWE-347
- Published
- 28 Sept 2026
- Updated
- 5 Oct 2026
No public PoC is confirmed on this record.
CVE-2026-96760 is a signature-verification bypass in Authlib’s JSON serialization of a JSON Web Signature. NVD and CERT/CC VU#762428 say JsonWebSignature.deserialize_json() can return a payload as verified when the signatures list is empty, without a cryptographic key. NVD scores it 9.8.
The affected range in those sources is 1.7.2 and earlier. CERT/CC first published the note on 28 September 2026. CISA has not listed the CVE. An Authlib pull request that describes a fix for empty-signature validation was still open, so this record does not name a released fixed version. Installing 1.6.9, which closes a different Authlib bug, does not close this one.