← Back to search

CVE-2026-96760

— UNSCOREDpublic exploit available

Published 2026-09-28 · Updated 2026-09-28

AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.

NVD description

Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key.

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.