CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-28802

Critical · CVSS 9.8

Authlib — JWT algorithm confusion / "alg:none" signature bypass (CWE-347 Improper Verification of Cryptographic Signature)

CVSS
9.8
nvd
EPSS
0.43%
35th pct
KEV
No
Class
oss containerizable
CWE-347, CWE-347

Description

Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature verification step without any changes to the application code when a failure was expected.. This issue has been patched in version 1.6.7.

Search profile — drives PoC discovery

Symbols alg: noneempty signaturesignature verificationJWTClaimsJsonWebTokendecodeverify_signatureJoseHeadernone algorithmauthlib.jose
Keywords CVE-2026-28802GHSA-7wc2-qxgw-g8ggAuthlib JWT alg none bypassAuthlib signature verification bypassAuthlib 1.6.5 1.6.6 JWT none algorithmAuthlib PoC exploitauthlib alg none empty signatureauthlib jose jwt bypass
Versions: 1.6.5 to < 1.6.7

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

Affected packages

PyPI authlib 1.6.5 → 1.6.7

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T06:30:14.000Z