Executive brief
joserfc is a Python library used to handle JSON Web Tokens (JWTs) and cryptographic signing operations. The library incorrectly validates the issuer claim when it is formatted as an array instead of a string, allowing attackers to forge tokens with a manipulated issuer claim that passes validation. This could allow an attacker to forge authentication tokens and impersonate trusted issuers.
Technical details
The vulnerability is a logic error in JWTClaimsRegistry's claim validation. The registry applies membership matching (array containment check) to list-valued claims including iss, sub, and jti, which RFC 7519 defines as single StringOrURI values. An attacker can craft a JWT with an array-typed iss claim containing both a malicious issuer and the expected legitimate issuer; the flawed membership check accepts this as a match when an equality check was intended. The vulnerability requires the application to rely on iss validation for authentication/authorization decisions, but no special privileges or user interaction are needed. The fix (version 1.7.3) adds type validation to reject array-typed iss, sub, jti, and nonce claims.
Affected products
- authlib joserfc before 1.7.3
Timeline
- 2026-08-24: disclosed
- 2026-07-03: patched: Fix committed; version 1.7.3 released