CriticalNo PoC
CVE-2026-96760
Authlib JSON signature list treated as verified
Auth bypass
Published 7d ago
Tracker
PoC, exploit, and active exploitation are separate statuses. If it is not confirmed, the record says Unknown or No PoC.
Filters match the recorded status. Active exploitation is not implied by a proof of concept.
Authlib JSON signature list treated as verified
Auth bypass
Published 7d ago
Authlib accepts a key embedded in the token
Auth bypass
Published 16 Mar 2026
Authlib none algorithm accepted on 1.6.5 and 1.6.6
Auth bypass
Published 6 Mar 2026