Authlib library contains a signature‑verification bypass security flaw
What happened
* Signed message injection between microservices using JWS. Overview Authlib (versions up to and including 1.7.2) contain a signature‑verification bypass in the JSON Web Signature (JWS) general JSON serialization handling.
The JsonWebSignature.deserialize_json() function accepts a JWS object with an empty "signatures" array and treats the payload as successfully verified, allowing attackers to supply arbitrary forged content without possessing any key material. Description Authlib is a Python library that provides tools for implementing OAuth, OpenID Connect, JWT/JWS/JWE (JSON Web Token / JSON Web Signature / JSON Web Encryption), and other modern authentication and authorization standards.
It’s widely used in web applications and microservices to handle token creation, cryptographic validation, and secure communication. As discussed in CVE-2026-96760 (the public catalogue number for a specific software flaw) , a security flaw in Authlib’s handling of JSON Web Signatures (JWS) makes it possible for an attacker to skip signature verification completely.
Sources & evidence
- CERT/CC Vulnerability Notes Primary / official
VU#762428: Authlib library contains a signature‑verification bypass vulnerability ↗
https://kb.cert.org/vuls/id/762428