CVE-2026-96760: Authlib
Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key.
Affected products
- Authlib Authlib: version 1.7.2 only
Published 2026-09-28. Last modified 2026-10-01.