CISA details Authlib JWS verification bypass affecting versions up to 1.7.2
2 companies named across 2 categories, one of 78 articles referencing GitHub. Previous coverage: CISA issues alert on Kotaemon improper authorization checks (Sep 2026).
Companies mentioned
Best suited for
- Seniority
- Director
- Job function
- Cybersecurity / Information Security
- Persona
- Security Operations Leader
- Buyer role
- Decision Maker / Budget Holder
- Buyer journey
- Open to Buy
- Adoption curve
- Laggards
- Technology maturity
- Established Technology
- Industry
- Information Technology / Cybersecurity / Application, Cloud & AI Security / Application Security & DevSecOps (SAST/DAST/SCA/Supply Chain)
Our classification, not the publisher's statement. Best suited for, not only for.
Authlib versions up to and including 1.7.2 contain a signature-verification bypass in JSON Web Signature (JWS) general JSON serialization handling, allowing forged JWS content to be treated as successfully verified without key material, which can lead to authentication and integrity failures.
The issue is tracked as CVE-2026-96760. In Authlib, the JsonWebSignature.deserialize_json() function accepts a JWS object with an empty “signatures” array and treats the payload as successfully verified. The function takes the signatures as valid and performs no checks when the list is empty, so it accepts unsigned data as properly signed. The same condition affects two ways of loading a JWS: jws.deserialize_json({“payload”:“...”, “signatures”:[]}, key=None) and jws.deserialize('{“payload”:“...”,“signatures”:[]}', key=None).
An attacker can forge arbitrary authenticated payloads without any signing key or credentials. Systems that rely on Authlib’s JWS verification for authentication, authorization, inter-service message integrity, or signed configuration data may accept attacker-supplied content as legitimate.
No official patch was made available at the time of this writing, and the vendor could not be reached to coordinate the vulnerability. Users are advised to monitor the project’s GitHub repository and install the latest version of the library once a fix has been released.
Security testing efforts in this advisory are associated with Authlib’s JWS general JSON serialization handling, specifically the behavior of deserialize_json() when the “signatures” field is an empty list.
Blog post, originally published by Bob Kemerer at kb.cert.org.