{"id":"PYSEC-2026-2118","details":"Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature verification step without any changes to the application code when a failure was expected.. This issue has been patched in version 1.6.7.","aliases":["CVE-2026-28802","GHSA-7wc2-qxgw-g8gg"],"modified":"2026-07-13T07:15:15.458932241Z","published":"2026-03-06T07:16:01.053Z","references":[{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2026-28802"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-28802.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:19375"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:4942"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:5168"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:5665"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:6309"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:6568"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2445120"},{"type":"FIX","url":"https://github.com/authlib/authlib/commit/a61c2acb807496e67f32051b5f1b1d5ccf8f0a75"},{"type":"FIX","url":"https://github.com/authlib/authlib/commit/b87c32ed07b8ae7f805873e1c9cafd1016761df7"},{"type":"EVIDENCE","url":"https://github.com/authlib/authlib/security/advisories/GHSA-7wc2-qxgw-g8gg"}],"affected":[{"package":{"name":"authlib","ecosystem":"PyPI","purl":"pkg:pypi/authlib"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.6.5"},{"fixed":"1.6.7"}]}],"versions":["1.6.5","1.6.6"],"ecosystem_specific":{},"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/authlib/PYSEC-2026-2118.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}