Skip to content
Ubuntu 24.04 LTS python-authlib Important Auth Bypass DoS USN-8065

Ubuntu 24.04 LTS python-authlib Important Auth Bypass DoS USN-8065

Linuxsecurity LinuxSecurity Advisories February 26, 2026

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Authlib. Software Description: - python-authlib: Python library for building OAuth and OpenID Connect servers Details: Millie Solem discovered that Authlib did not properly restrict algorithm selection during JWT verification, allowing HMAC verification with asymmetric public keys when no algorithm was specified. A remote attacker could possibly use this issue to bypass signature verification and forge tokens, resulting in authentication bypass or privilege escalation. (CVE-2024-37568) Muhammad Noman Ilyas discovered that Authlib did not properly enforce critical header parameter handling during JSON Web Signature verification, leading to unknown critical parameters being incorrectly accepted. A remote attacker could possibly use this issue to bypass security policies in mixed

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Authlib. Software Description: - python-authlib: Python library for building OAuth and OpenID Connect servers Details: Millie Solem discovered that Authlib did not properly restrict algorithm selection during JWT verification, allowing HMAC verification with asymmetric public keys when no algorithm was specified. A remote attacker could possibly use this issue to bypass signature verification and forge tokens, resulting in authentication bypass or privilege escalation. (CVE-2024-37568) Muhammad Noman Ilyas discovered that Authlib did not properly enforce critical header parameter handling during JSON Web Signature verification, leading to unknown critical parameters being incorrectly accepted. A remote attacker could possibly use this issue to bypass security policies in mixed

The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS python-authlib-doc 1.3.0-1ubuntu0.1~esm1 Available with Ubuntu Pro python3-authlib 1.3.0-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS python-authlib-doc 0.15.5-1ubuntu0.1~esm1 Available with Ubuntu Pro python3-authlib 0.15.5-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.

The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS python-authlib-doc 1.3.0-1ubuntu0.1~esm1 Available with Ubuntu Pro python3-authlib 1.3.0-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS python-authlib-doc 0.15.5-1ubuntu0.1~esm1 Available with Ubuntu Pro python3-authlib 0.15.5-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.

CVE-2024-37568, CVE-2025-59420, CVE-2025-61920, CVE-2025-62706, CVE-2025-68158

CVE-2024-37568, CVE-2025-59420, CVE-2025-61920, CVE-2025-62706,