CVE-2026-96760: Authlib

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key.

Affected products

  • Authlib Authlib: version 1.7.2 only

Published 2026-09-28. Last modified 2026-10-01.