Executive brief
joserfc is a Python library used by developers to handle secure digital tokens (JWTs) for authentication and data exchange. A flaw in how the library reads these tokens allows them to be slightly modified (by adding extra characters at the end) without breaking the security signature. This could allow an attacker to bypass security measures like "deny lists" or "revocation lists" because the modified token appears unique even though it represents the same user or session.
Technical details
The joserfc library (versions 1.7.1 and prior) incorrectly accepts JSON Web Tokens (JWTs) containing trailing base64 padding (==), which violates JOSE specifications. This results in token malleability, where multiple valid-looking encoded strings can represent the same underlying claims and signature. An attacker can exploit this to bypass security mechanisms that rely on token uniqueness, such as revocation deny-lists or anti-replay protections based on token hashes. While ECDSA signatures are inherently malleable, this flaw extends malleability to other signature and MAC schemes that would otherwise be rigid. The issue is resolved in version 1.7.2.
Affected products
- authlib joserfc <= 1.7.1
Timeline
- 2026-07-13: advisory: GitHub Security Advisory published
- 2026-07-29: disclosed: NVD publication date
- 2026-07-29: patched: Fix released in version 1.7.2