CVE-2026-28802

EUVD-2026-10009
Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature verification step without any changes to the application code when a failure was expected.. This issue has been patched in version 1.6.7.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 35.54%
Affected Products (NVD)
VendorProductVersion
authlibauthlib
1.6.5 ≤
𝑥
< 1.6.7
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Ansible Automation Platform 2.6
1774417022 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.1
1773971077 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.12
1773771962 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.15
1775169219 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.16
1779204086 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.9
1773936323 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
python-authlib
bookworm
1.2.0-1+deb12u1
fixed
bookworm (security)
1.2.0-1+deb12u2
fixed
bullseye
0.15.4-1
fixed
bullseye (security)
0.15.4-1+deb11u4
fixed
forky
1.7.2-2
fixed
sid
1.7.2-2
fixed
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-authlib
jammy
not-affected
noble
not-affected
questing
ignored
resolute
not-affected