Skip to main content

Mcpm: Authlib: JWS/JWT accepts unknown crit headers (RFC violation → possible authz bypass) (CVE-2025-59420)

0
High
Published: 08/13/2026 (08/13/2026, 17:13:14 UTC)
Source: GCVE Database
Product: mcpm

Description

Authlib version 1.6.3's JWS verification improperly accepts JSON Web Signatures (JWS) tokens containing unknown critical header parameters (`crit`), violating RFC 7515 requirements. This flaw allows tokens with critical headers that strict verifiers reject to be accepted, potentially causing authorization bypass in mixed-language environments. The vulnerability affects the `authlib.jose.JsonWebSignature.deserialize_compact(...)` API with default configuration. Exploitation can lead to split-brain verification scenarios, enabling replay or privilege escalation if critical security semantics are ignored.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected software

Homebrewmore threats →ghsa
mcpm
pkg:brew/mcpm
Affected versions
>=2.1.0 <2.8.2

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/18/2026, 01:55:30 UTC

Technical Analysis

Authlib's JWS verification does not enforce the RFC 7515 'must-understand' semantics for the `crit` header parameter. Specifically, when a token includes unknown critical headers such as `bork` or security-sensitive headers like `cnf`, Authlib 1.6.3 verifies the signature and returns the payload without rejecting the token or enforcing the semantics of these critical headers. This behavior contrasts with strict verifiers like Java Nimbus JOSE+JWT and Node jose, which reject tokens with unknown critical headers. In heterogeneous deployments, this discrepancy can cause a gateway to reject a token while a backend service using Authlib accepts it, leading to potential authorization bypass, replay attacks, or privilege escalation. The vulnerability is identified as CVE-2025-59420 with a CVSS 3.1 score of 7.5 (high severity).

Potential Impact

The vulnerability violates the JWS specification by accepting tokens with unknown critical headers, which should be rejected. This non-compliance can cause authorization policy bypass in environments where critical headers convey mandatory security semantics such as token binding (`cnf`). Services relying on Authlib 1.6.3 for JWS verification may accept malicious tokens rejected by other strict verifiers, resulting in split-brain acceptance. This can lead to replay attacks or privilege escalation if critical header semantics are ignored.

Mitigation Recommendations

A patch is available for this vulnerability. Users should upgrade Authlib to a fixed version that correctly enforces the RFC 7515 'must-understand' semantics for critical headers. Until patched, avoid relying on Authlib 1.6.3 for JWS verification in security-sensitive contexts involving critical headers. No vendor advisory content contradicts this guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
BREW-mcpm-CVE-2025-59420
Osv Schema Version
1.7.3
Ecosystems
["Homebrew"]
Cvss Version
3.1

Threat ID: 6aac8e4c55bf5e2cf5491426

Added to database: 09/18/2026, 01:05:16 UTC

Last enriched: 09/18/2026, 01:55:30 UTC

Last updated: 09/18/2026, 02:07:42 UTC

Views: 4

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses