Junglewise Threat Intelligence

CVE-2026-27962: Authlib JWK Header Injection signature verification bypass

CVE-2026-27962 · Severity: critical · CVSS 9.1 · Published 2026-03-16

Technologies: authlib (PyPI). Vendors: Red Hat, Authlib, PyPI.

Executive brief

Authlib, a popular Python library used to build secure login and identity services, contains a vulnerability that allows attackers to bypass authentication. By embedding a fake security key directly into a login token, an attacker can trick the server into accepting the token as valid. This allows an unauthorized person to impersonate any user or gain administrative access to applications using the library.

Technical details

A JWK Header Injection vulnerability exists in Authlib's JWS implementation prior to version 1.6.9. When the library's JWS deserialization functions (such as `deserialize_compact`) are called with `key=None`, the library incorrectly falls back to using the cryptographic key provided in the attacker-controlled `jwk` header field of the token. This allows an unauthenticated remote attacker to sign a token with their own private key, include the corresponding public key in the header, and successfully pass signature verification. This behavior violates RFC 7515, which requires verification keys to come from the application context rather than the token itself. The issue is particularly prevalent in JWKS-based lookups where a key resolver might return `None` for an unknown key ID (kid). The vulnerability is patched in version 1.6.9 by removing the automatic fallback to the header's JWK.

Affected products

  • Authlib Authlib < 1.6.9
  • Red Hat Red Hat Quay 3.1, 3.14, 3.15, 3.16

Timeline

  • 2026-03-02: patched: Version 1.6.9 released
  • 2026-03-15: advisory: GitHub Security Advisory published
  • 2026-03-16: disclosed: CVE-2026-27962 published to NVD

References

Related threats