Python authlib: From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing… (CVE-2026-28802)
A vulnerability in the Python Authlib library versions from 1.6.5 up to but not including 1.6.7 allowed malicious JWT tokens with 'alg: none' and empty signatures to bypass signature verification. This flaw was patched in version 1.6.7.
AI Analysis
Technical Summary
Python Authlib, a library for building OAuth and OpenID Connect servers, had a security flaw in versions 1.6.5 through before 1.6.7 where JWT tokens specifying 'alg: none' with empty signatures incorrectly passed signature verification. This allowed potentially unauthenticated tokens to be accepted without application code changes. The issue was fixed in version 1.6.7.
Potential Impact
An attacker could craft a malicious JWT token with 'alg: none' and an empty signature that would bypass signature verification, potentially leading to unauthorized access or privilege escalation in applications using the affected Authlib versions.
Mitigation Recommendations
Upgrade to Authlib version 1.6.7 or later, where this vulnerability has been patched. No other mitigations are indicated.
Python authlib: From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing… (CVE-2026-28802)
Description
A vulnerability in the Python Authlib library versions from 1.6.5 up to but not including 1.6.7 allowed malicious JWT tokens with 'alg: none' and empty signatures to bypass signature verification. This flaw was patched in version 1.6.7.
CVSS v3.1
Score 9.8critical
Affected software
pkg:deb/ubuntu/python-authlib?arch=source&distro=questingRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Python Authlib, a library for building OAuth and OpenID Connect servers, had a security flaw in versions 1.6.5 through before 1.6.7 where JWT tokens specifying 'alg: none' with empty signatures incorrectly passed signature verification. This allowed potentially unauthenticated tokens to be accepted without application code changes. The issue was fixed in version 1.6.7.
Potential Impact
An attacker could craft a malicious JWT token with 'alg: none' and an empty signature that would bypass signature verification, potentially leading to unauthorized access or privilege escalation in applications using the affected Authlib versions.
Mitigation Recommendations
Upgrade to Authlib version 1.6.7 or later, where this vulnerability has been patched. No other mitigations are indicated.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-28802
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:25.10"]
- Cvss Version
- 3.1
Threat ID: 6aa2af7eacd9273b4925ad88
Added to database: 09/10/2026, 13:24:14 UTC
Last enriched: 09/10/2026, 13:34:45 UTC
Last updated: 09/10/2026, 19:30:01 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.