Back Linuxsecurity Ubuntu 24.04 LTS python-authlib Important Auth Bypass DoS USN-8065
A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Authlib. Software Description: - python-authlib: Python library for building OAuth and OpenID Connect servers Details: Millie Solem discovered that Authlib did not properly restrict algorithm selection during JWT verification, allowing HMAC verification with asymmetric public keys when no algorithm was specified. A remote attacker could possibly use this issue to bypass signature verification and forge tokens, resulting in authentication bypass or privilege escalation. (CVE-2024-37568) Muhammad Noman Ilyas discovered that Authlib did not properly enforce critical header parameter handling during JSON Web Signature verification, leading to unknown critical parameters being incorrectly accepted. A remote attacker could possibly use this issue to bypass security policies in mixed
A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Authlib. Software Description: - python-authlib: Python library for building OAuth and OpenID Connect servers Details: Millie Solem discovered that Authlib did not properly restrict algorithm selection during JWT verification, allowing HMAC verification with asymmetric public keys when no algorithm was specified. A remote attacker could possibly use this issue to bypass signature verification and forge tokens, resulting in authentication bypass or privilege escalation. (CVE-2024-37568) Muhammad Noman Ilyas discovered that Authlib did not properly enforce critical header parameter handling during JSON Web Signature verification, leading to unknown critical parameters being incorrectly accepted. A remote attacker could possibly use this issue to bypass security policies in mixed
The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS python-authlib-doc 1.3.0-1ubuntu0.1~esm1 Available with Ubuntu Pro python3-authlib 1.3.0-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS python-authlib-doc 0.15.5-1ubuntu0.1~esm1 Available with Ubuntu Pro python3-authlib 0.15.5-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.
The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS python-authlib-doc 1.3.0-1ubuntu0.1~esm1 Available with Ubuntu Pro python3-authlib 1.3.0-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS python-authlib-doc 0.15.5-1ubuntu0.1~esm1 Available with Ubuntu Pro python3-authlib 0.15.5-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.
CVE-2024-37568, CVE-2025-59420, CVE-2025-61920, CVE-2025-62706, CVE-2025-68158
CVE-2024-37568, CVE-2025-59420, CVE-2025-61920, CVE-2025-62706,
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
