{"id":"CVE-2026-96760","summary":"Authlib library contains a signature‑verification bypass vulnerability","details":"Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key.","modified":"2026-09-29T11:48:14.732418588Z","published":"2026-09-28T19:37:58.973Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/96xxx/CVE-2026-96760.json","cna_assigner":"certcc"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/96xxx/CVE-2026-96760.json"},{"type":"PACKAGE","url":"https://github.com/authlib/authlib"},{"type":"WEB","url":"https://kb.cert.org/vuls/id/762428"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-96760"},{"type":"WEB","url":"https://www.kb.cert.org/vuls/id/762428"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/authlib/authlib","events":[{"introduced":"a0b76fac3fa114d7759af2010546bfc332364b63"},{"last_affected":"a0b76fac3fa114d7759af2010546bfc332364b63"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"1.7.2"},{"last_affected":"1.7.2"}]}}],"versions":["1.7.2","v1.7.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-96760.json"}}],"schema_version":"1.9.0"}