CVE-2026-28802Disclosure(authlib / authlib)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch authlib authlib systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature verification step without any changes to the application code when a failure was expected.. This issue has been patched in version 1.6.7.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-347

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • authlib

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 2 mentions (2026-03-06); latest day: 2
  • 8 total mentions across 6 days

Affected systems

Vendors
Products
authlib

Deep dive

Activity timeline8 mentions / 6d
01122Mentions · 2026-03-06: 2Mentions · 2026-03-09: 1Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Mentions · 2026-03-25: 1Mentions · 2026-09-29: 2Patch / Workaround · 2026-09-29: 2Technical Details · 2026-03-06: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-25: 1Technical Details · 2026-09-29: 203-0603-0903-1003-1103-2509-29
Signal classification3 categories
Disclosure
450.0%
General
225.0%
Patch
225.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-062
Disclosure1General1
2026-03-091
Disclosure1
2026-03-101
Disclosure1
2026-03-111
General1
2026-03-251
Disclosure1
2026-09-292
Patch2
Full discourse8 posts
  • ThreatWire@ThreatWire_
    Patch

    🚨 SECURITY ALERT: Multiple Authlib signature-verification flaws can allow forged JWS/JWT payloads to bypass cryptographic validation. • CVE-2026-96760 — Authlib ≤ 1.7.2 • CVE-2026-27962 — fixed in 1.6.9 • CVE-2026-28802 — fixed in 1.6.7 The flaws can undermine signature verification and, depending on how Authlib is used, impact authentication and authorization. 🔴 Update Authlib to a patched version. #CVE #CyberSecurity #InfoSec #Python #Authlib

    Post summary

    The tweet alerts to three Authlib signature‑verification vulnerabilities (CVE‑2026‑96760, CVE‑2026‑27962, CVE‑2026‑28802) and advises updating to a patched version, with no mention of PoC, exploit code, or active exploitation.

    010115897
    1.8K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    An Authlib signature bypass vulnerability (CVE-2026-96760, CVE-2026-28802, CVE-2026-27962) lets attackers forge JWS payloads. Update libraries now. #Authlib #CVE202696760 #Cybersecurity #JWS #Vulnerability https://securityonline.info/authlib-signature-bypass-vulnerability/

    Post summary

    The tweet reports multiple Authlib signature bypass CVEs that enable forging JWS payloads and explicitly advises updating libraries as the remediation step.

    01023459
    13.0K followersView on X
  • cypher aes@AesCypher91366
    Disclosure

    My latest cve, from #authlib The heart of CVE-2026-27962 is a critical signature verification bypass. For a deep dive into the mechanics of this exploit, check out this cool blog by Armo: https://www.armosec.io/blog/authlib-cve-2026-28802-jwt-signature-verification-bypass/ #cybersecurity #0day #bugbounty #hacking

    Post summary

    The post announces a new Authlib CVE involving a signature verification bypass and points to a blog for further details.

    0000046
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-28802 (CVSS:7.7, CRITICAL) is Analyzed. Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, p..https://nvd.nist.gov/vuln/detail/CVE-2026-28802 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-28802 and its CVSS score, but does not mention a PoC, exploit, or patch.

    0000031
    172 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Authlib, Signature Verification Bypass, #CVE-2026-28802 (Critical) https://dailycve.com/authlib-signature-verification-bypass-cve-2026-28802-critical/

    Post summary

    The text announces a critical signature verification bypass (CVE-2026-28802) in Authlib but provides only minimal technical details without any evidence of exploits, tools, or mitigation guidance.

    0000036
    167 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-28802 - Critical Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: non... https://www.thehackerwire.com/vulnerability/CVE-2026-28802/ https://t.co/tKJiJG9sVM

    Post summary

    The text announces a critical vulnerability (CVE‑2026‑28802) in Authlib’s JWT handling, noting affected versions, but offers no PoC, exploitation details, or patch information.

    0000038
    129 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-28802 Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JW… https://www.cve.org/CVERecord?id=CVE-2026-28802

    Post summary

    The provided text cites CVE-2026-28802 with affected Authlib versions but offers no PoC, exploitation details, or patch information, leaving the content largely generic.

    00000137
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28802 Signature Bypass Vulnerability in Authlib OAuth Library Versions 1.6.5-1.6.7 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28802

    Post summary

    The text announces CVE-2026-28802, a signature bypass vulnerability in Authlib OAuth Library 1.6.5‑1.6.7, and links to an external vulnerability details page.

    0000044
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appauthlibauthlib---

Explore more