CVE-2026-96760 — Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability.
Description
Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCritical severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
None
Privileges Required
UI
None
User Interaction
S
Unchanged
Scope
C
High
Confidentiality
I
High
Integrity
A
High
Availability
References
Related threats
same CWE or vendorCVE-2026-107726 — Hazelcast is a unified real-time data platform combining stream processing with a fast data store.
CVE-2026-107726 · 2h ago
CVE-2026-107724 — fast-jwt provides fast JSON Web Token (JWT) implementation.
CVE-2026-107724 · 2h ago
CVE-2026-107722 — fast-jwt provides fast JSON Web Token (JWT) implementation.
CVE-2026-107722 · 2h ago
CVE-2026-107720 — fast-jwt provides fast JSON Web Token (JWT) implementation.
CVE-2026-107720 · 2h ago
CVE-2026-107717 — Banks generates meaningful LLM prompts using a simple template language.
CVE-2026-107717 · 2h ago
Coraza: URL-encoded form Content-Type parameters bypass Coraza body inspection
OSV · 7h ago