securityonline.info 29 Sept 2026, 01:59 UTC

Authlib Flaw Lets Attackers Forge Signed Messages Without Keys

Authlib Flaw Lets Attackers Forge Signed Messages Without Keys
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

CERT /CC has warned of a signature-bypass vulnerability in Authlib, a Python library used to implement OAuth, OpenID Connect and JWT/JWS standards. Tracked as CVE-2026-96760, the flaw could allow attackers to create JSON Web Signatures (JWS) containing arbitrary payloads without possessing signing keys or credentials.

Applications and microservices that rely on Authlib to validate signed content could therefore accept attacker-controlled data as legitimate, potentially enabling forged authorisation claims, malicious service messages and integrity bypasses. The report does not state that exploitation has been confirmed.

The defect affects Authlib versions up to and including 1.7.2. According to the advisory, the problem lies in handling JWS general JSON serialisation: the `deserialize_json()` function accepts objects with an empty `signatures` array, assumes signatures are valid, and skips verification when none are present. Both the `jws.deserialize_json()` and `jws.deserialize()` loading methods are reported as vulnerable. An attacker needs only to submit a specially crafted JWS with no signatures for the payload to be treated as authenticated.

No official fix was available when the report was published, reportedly because coordinators were unable to reach the vendor. Users of affected versions should monitor the Authlib GitHub repository for a release and update as soon as a patch becomes available.

View full article

Article by CyberSIXT