
🚨 SECURITY ALERT: Multiple Authlib signature-verification flaws can allow forged JWS/JWT payloads to bypass cryptographic validation. • CVE-2026-96760 — Authlib ≤ 1.7.2 • CVE-2026-27962 — fixed in 1.6.9 • CVE-2026-28802 — fixed in 1.6.7 The flaws can undermine signature verification and, depending on how Authlib is used, impact authentication and authorization. 🔴 Update Authlib to a patched version. #CVE #CyberSecurity #InfoSec #Python #Authlib


