CVE-2026-27962Disclosure(authlib / authlib)

LOWCVSS 9.1 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch authlib authlib systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrary JWT tokens that pass signature verification. When key=None is passed to any JWS deserialization function, the library extracts and uses the cryptographic key embedded in the attacker-controlled JWT jwk header field. An attacker can sign a token with their own private key, embed the matching public key in the header, and have the server accept the forged token as cryptographically valid — bypassing authentication and authorization entirely. This issue has been patched in version 1.6.9.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • authlib

Threat summary

  • Patch or workaround signal is available
  • 12 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 10 signals
  • Disclosure: 6 classified signals
  • False Positive: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-03-17); latest day: 2
  • 12 total mentions across 5 days

Affected systems

Vendors
Products
authlib

Deep dive

Activity timeline12 mentions / 5d
01234Mentions · 2026-03-16: 3Mentions · 2026-03-17: 4Mentions · 2026-03-25: 1Mentions · 2026-09-22: 2Mentions · 2026-09-29: 2Patch / Workaround · 2026-03-16: 1Patch / Workaround · 2026-03-17: 3Patch / Workaround · 2026-09-22: 1Technical Details · 2026-03-16: 3Technical Details · 2026-03-17: 4Technical Details · 2026-03-25: 1Technical Details · 2026-09-22: 203-1603-1703-2509-2209-29
Signal classification3 categories
Disclosure
660.0%
Patch
330.0%
False Positive
110.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-163
Disclosure2Patch1
2026-03-174
Disclosure3Patch1
2026-03-251
Disclosure1
2026-09-222
False Positive1Patch1
Full discourse12 posts
  • ThreatWire@ThreatWire_

    🚨 SECURITY ALERT: Multiple Authlib signature-verification flaws can allow forged JWS/JWT payloads to bypass cryptographic validation. • CVE-2026-96760 — Authlib ≤ 1.7.2 • CVE-2026-27962 — fixed in 1.6.9 • CVE-2026-28802 — fixed in 1.6.7 The flaws can undermine signature verification and, depending on how Authlib is used, impact authentication and authorization. 🔴 Update Authlib to a patched version. #CVE #CyberSecurity #InfoSec #Python #Authlib

    010115897
    1.8K followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    An Authlib signature bypass vulnerability (CVE-2026-96760, CVE-2026-28802, CVE-2026-27962) lets attackers forge JWS payloads. Update libraries now. #Authlib #CVE202696760 #Cybersecurity #JWS #Vulnerability https://securityonline.info/authlib-signature-bypass-vulnerability/

    01023457
    13.0K followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Disclosure

    6 critical vulnerabilities (CVSS 9.0+) disclosed 3/16-17, including CVE-2026-27962 Authlib JWT signature bypass enabling complete OAuth/OIDC authentication bypass.

    Post summary

    The post announces six critical vulnerabilities disclosed on March 16‑17, including CVE-2026-27962, a JWT signature bypass in Authlib that allows full OAuth/OIDC authentication bypass.

    1001057
    8 followersView on X
  • CVE Brief@DailyCVEBrief
    Patch

    LOOK BACK: In 2020, Authlib added two lines letting a JWT header supply the key used to verify that same JWT. A 2022 fix narrowed the condition. In Feb 2026 it was finally deleted. CVE-2026-27962, CVSS 9.1, and six months on nobody has been seen exploiting it. https://t.co/9cHasqsscu

    Post summary

    The tweet outlines the history of CVE‑2026‑27962, a JWT verification flaw that was patched in 2022, fully removed in Feb 2026, and remains unexploited despite its high CVSS 9.1 rating.

    1000052
    32 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Three critical flaws in Authlib (including CVSS 9.1 CVE-2026-27962) allow JWT forgery and padding oracle attacks. Update to version 1.6.9 immediately. #Authlib #JWTSecurity #CVE #PythonSecurity #CyberSecurity #OAuth #OIDC #PaddingOracle #Vulnerability https://securityonline.info/broken-keys-critical-authlib-flaws-jwt-forgery-padding-oracles/ https://t.co/WhcfNyA39K

    Post summary

    The tweet announces three critical Authlib flaws (JWT forgery and padding oracle, CVSS 9.1) and urges a prompt update to version 1.6.9, without providing exploit code or evidence of active exploitation.

    00010350
    10.7K followersView on X
  • CVE Brief@DailyCVEBrief
    False Positive

    Full Look Back: the trigger the advisory describes that does not exist in the code, why Red Hat rated it Low, and the second fix in the same commit that no advisory mentions: https://cvebrief.com/cve/cve-2026-27962/ https://t.co/HS3aR3VW51

    Post summary

    The tweet critiques the CVE advisory by highlighting that the described trigger is absent from the code, notes Red Hat’s low severity rating, and mentions an unmentioned second fix, implying the vulnerability may be a false positive or less severe than reported.

    0000038
    32 followersView on X
  • cypher aes@AesCypher91366
    Disclosure

    My latest cve, from #authlib The heart of CVE-2026-27962 is a critical signature verification bypass. For a deep dive into the mechanics of this exploit, check out this cool blog by Armo: https://www.armosec.io/blog/authlib-cve-2026-28802-jwt-signature-verification-bypass/ #cybersecurity #0day #bugbounty #hacking

    Post summary

    The tweet announces CVE-2026-27962, a critical signature verification bypass in Authlib, and points readers to a blog post for a deeper technical dive.

    0000046
  • PulsePatch.io@pulsepatchio
    Disclosure

    A critical signature bypass (CVE-2026-27962) affects `Authlib` JWS JWK header validation. Systems using `Authlib` for JWS verification may be vulnerable to forged tokens. Monitor for patches. #Authlib #JWS #SecurityAdvisory https://www.pulsepatch.io/posts/cve-2026-27962-authlib-signature-bypass

    Post summary

    The advisory announces a critical signature bypass in Authlib’s JWS validation, warns of forged token risk, and urges monitoring for forthcoming patches.

    0000044
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27962 Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementatio… https://www.cve.org/CVERecord?id=CVE-2026-27962

    Post summary

    CVE-2026-27962 describes a JWK Header Injection flaw in Authlib’s JWS implementation, with the issue fixed in version 1.6.9.

    00000126
    56.7K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-27962 - Critical Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthent... https://www.thehackerwire.com/vulnerability/CVE-2026-27962/ https://t.co/cN4JsR8H4J

    Post summary

    A critical JWK Header Injection vulnerability in Authlib's JWS implementation (CVE-2026-27962) is disclosed, affecting versions prior to 1.6.9.

    0000067
    136 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-27962: CRITICAL] Vulnerability in Authlib's JWS implementation (pre v1.6.9) allows unauthenticated attacker to forge JWT tokens due to JWK Header Injection issue. Update to version 1.6.9 to patch.#cve,CVE-2026-27962,#cybersecurity https://cvefind.com/CVE-2026-27962

    Post summary

    Authlib’s JWS implementation is vulnerable to JWK Header Injection, enabling attackers to forge JWT tokens; updating to version 1.6.9 patches the issue.

    0000066
    601 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-27962: Authlib JWS JWK Header Injection... Authlib's JWK header injection lets attackers self-sign JWTs with embedded public keys, turning `key=None` into complet... https://zerodaysignal.com/vulnerability/CVE-2026-27962 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑27962, highlighting a JWK header injection flaw in Authlib that enables attackers to forge JWTs by injecting public keys. No PoC, exploit code, patch, or evidence of active exploitation is provided.

    0000087
    151 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appauthlibauthlib---

Explore more