Bug 2542633 (CVE-2026-96760)

Summary: CVE-2026-96760 authlib: authlib: Signature verification bypass via deserialize_json
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: anpicker, anthomas, bparees, dfreiber, dkeler, doconnor, drow, dschmidt, ebourniv, ehelms, ggainey, hasun, ikhan, ilpinto, jburrell, jfula, jlanda, jowilson, jpasqual, juwatts, kshier, ltomasbo, mdellweg, mhayden, mhulan, nmoumoul, nyancey, ometelka, osousa, pcreech, ptisnovs, rbobbitt, rchan, rjohnson, sbunciak, sdoran, simaishi, smallamp, stcannon, suppawar, syedriko, thason, tmalecek, vkumar, xdharmai, yguenane, ykashtan
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in authlib. This flaw allows a remote attacker to bypass digital signature verification and submit forged data. When processing a JSON Web Signature (JWS, a format used to verify data integrity), the deserialize_json() function marks payloads as successfully verified without validating cryptographic signatures or requiring a verification key. Consequently, an attacker can supply manipulated data that the application treats as authentic and trusted, potentially leading to unauthorized access.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-28 19:57:48 UTC
Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signature and without requiring a cryptographic key.