An empty signature list can make Authlib accept attacker-authored JWS content as authenticated.
Affects
Authlib, a cross-platform Python library used by web applications and microservices for OAuth, OpenID Connect, JWT and JWS handling.
The general-JSON deserializer begins in a successful state and performs no verification loop iteration when signatures is empty, so it returns an unsigned payload as verified.
Detail and 2 sources
A relying application can turn that result into forged identities, roles, scopes, inter-service messages, or configuration.
Public code demonstrates the bypass, no patch is available in the reviewed material, and we do not know how commonly applications expose this Authlib path.
Chain to watch
An application accepts JWS general JSON through Authlib→↓Authlib accepts an empty signatures array without verification→↓The application trusts the returned payload for authentication or authorization→↓Deployment of the affected general-JSON path is unknown.
Unverified chainInventory Authlib consumers that accept JWS general JSON and reject objects with no signatures at the application boundary.
The same brief, every morning. One email a day, nothing else.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.