Linuxsecurity
Ubuntu Authlib Vulnerabilities Lead to Authentication Bypass Risk
First seen 26 Feb 2026, 22:13 UTC
•
•86% similarity
•20.3
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
A security issue was identified in the Authlib library affecting Ubuntu 24.04 LTS and 22.04 LTS. Discovered by Millie Solem, the vulnerability allows HMAC verification with asymmetric public keys during JWT verification, potentially enabling remote attackers to bypass authentication and forge tokens. The issue is tracked as CVE-2024-37568.
ThreatCluster AI
Timeline
2024-06-09
CVE-2024-37568 published
2025-09-22
CVE-2025-59420 published
2025-10-10
CVE-2025-61920 published
2025-10-22
CVE-2025-62706 published
2026-01-08
CVE-2025-68158 published
2026-02-25
Ubuntu announces Authlib vulnerabilities
2026-02-26
Linuxsecurity reports on Authlib vulnerabilities