Skip to content

Fix empty signatures validation in JWS JSON deserialization - #938

Open
loporto wants to merge 1 commit into
authlib:mainfrom
loporto:candidate/cve-2026-96760
Open

loporto wants to merge 1 commit into
authlib:mainfrom
loporto:candidate/cve-2026-96760

Conversation

@loporto

@loporto loporto commented Oct 1, 2026

Copy link
Copy Markdown

Hi, found a Critical security issue (Critical according Snyk)
Here is vulnerability https://www.cve.org/CVERecord?id=CVE-2026-96760
Basically if passing empty signatures current version validates, which is the vulnerability.
Made small change in jws.py file and include a test case under test_jws.py which fails if fix is not applied.
Please if it is possible to fix and send a new release as soon as possible, I will appreciate. Thanks.

@sidagrawal94

Copy link
Copy Markdown

bump

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants