{"document":{"acknowledgments":[{"urls":["https://kb.cert.org/vuls/id/762428#acknowledgements"]}],"category":"CERT/CC Vulnerability Note","csaf_version":"2.0","notes":[{"category":"summary","text":"### Overview\r\nAuthlib (versions up to and including 1.7.2) contain a signature‑verification bypass in the JSON Web Signature (JWS) general JSON serialization handling. The `JsonWebSignature.deserialize_json()` function accepts a JWS object with an empty \"signatures\" array and treats the payload as successfully verified, allowing attackers to supply arbitrary forged content without possessing any key material.\r\n\r\n### Description\r\nAuthlib is a Python library that provides tools for implementing OAuth, OpenID Connect, JWT/JWS/JWE (JSON Web Token / JSON Web Signature / JSON Web Encryption), and other modern authentication and authorization standards. It’s widely used in web applications and microservices to handle token creation, cryptographic validation, and secure communication. \r\n\r\nAs discussed in **CVE-2026-96760**, a security flaw in Authlib’s handling of JSON Web Signatures (JWS) makes it possible for an attacker to skip signature verification completely. Normally, a JWS should include at least one valid signature to prove the data hasn’t been tampered with. However, Authlib’s `deserialize_json()` function mistakenly accepts JWS objects even when the \"signatures\" section is an empty list. Because the function starts by assuming the signatures are valid and never performs any checks when the list is empty, it ends up treating unsigned data as if it were properly signed. This means an attacker could provide a JWS with no signatures, and Authlib would still treat it as trusted. Both ways of loading a JWS in Authlib are affected:\r\n\r\n`jws.deserialize_json({\"payload\":\"...\", \"signatures\":[]}, key=None)`\r\n`jws.deserialize('{\"payload\":\"...\",\"signatures\":[]}', key=None)`\r\n\r\n### Impact\r\nAn attacker can forge arbitrary authenticated payloads without any signing key or credentials. Systems that rely on Authlib’s JWS verification for authentication, authorization, inter-service message integrity, or signed configuration data may accept attacker‑supplied content as legitimate. Potential attack scenarios inlcude the following:\r\n* Authentication bypass: forged identity or privilege‑escalation claims (e.g., sub=admin).\r\n* Signed message injection between microservices using JWS.\r\n* Forged authorization claims such as scopes, roles, or permissions.\r\n* Integrity bypass in systems relying on signed JWS data.\r\n\r\n### Solution\r\nThe vendor could not be reached to coordinate this vulnerability and an official patch has not been made available at the time of this writing. Users are advised to monitor the project's GitHub repository for updates and install the latest version of this library once a fix has been released.\r\n\r\n### Acknowledgements\r\nThank you to Tong Hoang Gia (uziii2208) and Nguyen Minh Tuan (nguyenminhtuan28) for reporting this vulnerability. This document was written by Bob Kemerer.","title":"Summary"},{"category":"legal_disclaimer","text":"THIS DOCUMENT IS PROVIDED ON AN 'AS IS' BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. ","title":"Legal Disclaimer"},{"category":"other","text":"CERT/CC Vulnerability Note is a limited advisory. It primarily identifies vendors impacted by the advisory and not specific products. We only support \"known_affected\" and \"known_not_affected\" status. Please consult the vendor's statements and advisory URL if provided by the vendor for more details ","title":"Limitations of Advisory"}],"publisher":{"category":"coordinator","contact_details":"Email: cert@cert.org, Phone: +1412 268 5800","issuing_authority":"CERT/CC under DHS/CISA https://www.cisa.gov/cybersecurity also see https://kb.cert.org/ ","name":"CERT/CC","namespace":"https://kb.cert.org/"},"references":[{"url":"https://certcc.github.io/certcc_disclosure_policy","summary":"CERT/CC vulnerability disclosure policy"},{"summary":"CERT/CC document released","category":"self","url":"https://kb.cert.org/vuls/id/762428"},{"url":"https://github.com/authlib/authlib","summary":"https://github.com/authlib/authlib"}],"title":"Authlib library contains a signature‑verification bypass vulnerability","tracking":{"current_release_date":"2026-09-28T19:36:11+00:00","generator":{"engine":{"name":"VINCE","version":"3.0.49"}},"id":"VU#762428","initial_release_date":"2026-09-28 19:36:11.292441+00:00","revision_history":[{"date":"2026-09-28T19:36:11+00:00","number":"1.20260928193611.1","summary":"Released on 2026-09-28T19:36:11+00:00"}],"status":"final","version":"1.20260928193611.1"}},"vulnerabilities":[{"title":"Authlib (v1.","notes":[{"category":"summary","text":"Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key."}],"cve":"CVE-2026-96760","ids":[{"system_name":"CERT/CC V Identifier ","text":"VU#762428"}]}],"product_tree":{"branches":[]}}