WORLDTECH NEWS Global technology intelligence.Contact
← Back to WORLDTECH

Authlib library contains a signature‑verification bypass security flaw

System with various wires managing access to centralized resource of server in data center
Illustrative photo.Photo by Brett Sayles on Pexels

What happened

* Signed message injection between microservices using JWS. Overview Authlib (versions up to and including 1.7.2) contain a signature‑verification bypass in the JSON Web Signature (JWS) general JSON serialization handling.

The JsonWebSignature.deserialize_json() function accepts a JWS object with an empty "signatures" array and treats the payload as successfully verified, allowing attackers to supply arbitrary forged content without possessing any key material. Description Authlib is a Python library that provides tools for implementing OAuth, OpenID Connect, JWT/JWS/JWE (JSON Web Token / JSON Web Signature / JSON Web Encryption), and other modern authentication and authorization standards.

It’s widely used in web applications and microservices to handle token creation, cryptographic validation, and secure communication. As discussed in CVE-2026-96760 (the public catalogue number for a specific software flaw) , a security flaw in Authlib’s handling of JSON Web Signatures (JWS) makes it possible for an attacker to skip signature verification completely.

Sources & evidence