Index
Search
Search the public record. Drafts and scheduled notes are not included.
Critical
research
Three Authlib signature bugs are not one patch
CVE-2026-28802, CVE-2026-27962, and CVE-2026-96760 are separate Authlib signature failures. Two have releases. The newest, through 1.7.2, does not.
Published 2h ago
CriticalNo PoC
CVE-2026-96760
Authlib JSON signature list treated as verified
Auth bypass
Published 7d ago
CriticalNo PoC
CVE-2026-27962
Authlib accepts a key embedded in the token
Auth bypass
Published 16 Mar 2026
HighNo PoC
CVE-2026-28802
Authlib none algorithm accepted on 1.6.5 and 1.6.6
Auth bypass
Published 6 Mar 2026