Three Authlib signature bugs are not one patch
CVE-2026-28802, CVE-2026-27962, and CVE-2026-96760 are separate Authlib signature failures. Two have releases. The newest, through 1.7.2, does not.
Published 5 Oct 2026
What happened
A single alert named three Authlib flaws. They are three records, published months apart, and they do not share a fix.
CVE-2026-28802 was published to NVD on 6 March 2026. GitHub advisory GHSA-7wc2-qxgw-g8gg says Authlib 1.6.5 and 1.6.6 can accept a JWT that uses the none algorithm with an empty signature. NVD’s CVSS 4.0 score is 7.7.
CVE-2026-27962 was published on 16 March 2026. Advisory GHSA-wvwj-cvrp-7pv5 says that if the application passes no key, Authlib through 1.6.8 can verify a token using a key embedded in that token. NVD scores it 9.1.
CVE-2026-96760 was published on 28 September 2026. CERT/CC VU#762428 says deserialize_json() in Authlib through 1.7.2 can treat a JSON Web Signature with an empty signatures list as already verified. NVD scores it 9.8.
Who is affected
Each range is narrow. CVE-2026-28802 is 1.6.5 and 1.6.6 only. CVE-2026-27962 is versions before 1.6.9, and only on the path where verification is called without an application key. CVE-2026-96760 is 1.7.2 and earlier on the JSON deserialization path.
An application that pins 1.6.9 or later is outside the first two ranges and still inside the third if it has not moved past 1.7.2. An application that never verifies tokens with Authlib is outside all three.
What is confirmed
The 1.6.7 release is the patch NVD names for CVE-2026-28802. The 1.6.9 release is the patch it names for CVE-2026-27962. Both advisories describe authentication and authorization impact when an application trusts the library’s answer. CISA’s Known Exploited Vulnerabilities catalog lists none of the three. No public proof-of-concept repository was confirmed for them, so each record is No PoC.
What is not confirmed
There is no released version that this desk can cite as the fix for CVE-2026-96760. Authlib pull request 938, which describes empty-signature validation, was still open. PyPI showing a later Authlib release is not the same fact as that pull request being merged. Moving to 1.6.9 does not close CVE-2026-96760.
The alert’s line that the flaws “can allow forged JWS/JWT payloads” matches the advisories. It does not make the three bugs interchangeable, and it does not put them in the CISA catalog.
What to do
Install 1.6.7 or later for CVE-2026-28802, and 1.6.9 or later for CVE-2026-27962. For CVE-2026-96760, do not treat a current release as patched until the project ships a version that includes the empty-signatures check. Until then, do not rely on deserialize_json() as proof that a JSON Web Signature was signed.
Sources: CERT/CC VU#762428, Authlib advisories GHSA-7wc2-qxgw-g8gg and GHSA-wvwj-cvrp-7pv5, the 1.6.9 release, NVD for the three CVE ids, and Authlib pull request 938.
Related CVEs
- CVE-2026-96760 — Authlib JSON signature list treated as verified
- CVE-2026-27962 — Authlib accepts a key embedded in the token
- CVE-2026-28802 — Authlib none algorithm accepted on 1.6.5 and 1.6.6