Back Linuxsecurity Ubuntu 26.04 Authlib Important JWT Bypass and CSRF Vulnerities USN-8557
Several security issues were fixed in Authlib. Software Description: - python-authlib: Python library for building OAuth and OpenID Connect servers Details: Jay Neiva and Mauro Carrillo discovered that Authlib did not properly validate cryptographic keys embedded in JWT headers. An attacker could possibly use this issue to forge trusted tokens, resulting in authentication and authorization bypass. (CVE-2026-27962) Jay Neiva and Mauro Carrillo discovered that Authlib incorrectly handled RSA1_5 encrypted tokens. An attacker could possibly use this issue to recover sensitive encrypted information, resulting in information disclosure. (CVE-2026-28490) Jay Neiva and Mauro Carrillo discovered that Authlib did not properly reject unsupported cryptographic algorithms when validating OpenID Connect ID tokens. An attacker could possibly use this issue to bypass token integrity checks, resulting in authentication bypass. (CVE-2026-28498) Johnny Deuss discovered that Authlib did not prov... Read the Full Advisory
Several security issues were fixed in Authlib.
Software Description:
- python-authlib: Python library for building OAuth and OpenID Connect servers
Jay Neiva and Mauro Carrillo discovered that Authlib did not properly
validate cryptographic keys embedded in JWT headers. An attacker could
possibly use this issue to forge trusted tokens, resulting in
authentication and authorization bypass. (CVE-2026-27962)
Jay Neiva and Mauro Carrillo discovered that Authlib incorrectly handled
RSA1_5 encrypted tokens. An attacker could possibly use this issue to
recover sensitive encrypted information, resulting in information
disclosure. (CVE-2026-28490)
Jay Neiva and Mauro Carrillo discovered that Authlib did not properly
reject unsupported cryptographic algorithms when validating OpenID
Connect ID tokens. An attacker could possibly use this issue to bypass
token integrity checks, resulting in authentication bypass.
Johnny Deuss discovered that Authlib did not prov...
The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS python3-authlib 1.6.7-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 24.04 LTS python3-authlib 1.3.0-1ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 22.04 LTS python3-authlib 0.15.5-1ubuntu0.1~esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.
CVE-2026-27962, CVE-2026-28490, CVE-2026-28498, CVE-2026-41425
Ubuntu Security Notice USN-8557-1
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
