Overview Authlib (versions up to and including 1.7.2) contain a signature‑verification bypass in the JSON Web Signature (JWS) general JSON serialization handling. The JsonWebSignature.deserialize_json() function accepts a JWS object with an empty "signatures" array and treats the payload as successfully verified, allowing attackers to supply arbitrary forged content without possessing any key material.
VU#762428: Authlib library contains a signature‑verification bypass vulnerability
About this summary. This is a short, independently written summary of an article first published by CERT/CC. Cyber Security News did not report or verify the underlying story. Read the original: https://kb.cert.org/vuls/id/762428
Source attribution: headline and facts are from CERT/CC (kb.cert.org). Summary method: excerpt of the source description. See our source attribution policy.




