Skip to finding
important · Edge — identity

An empty JWS signature array makes Authlib return attacker-controlled payloads as verified.

Affects

Authlib, a Python OAuth, OpenID Connect and JOSE library used by web applications and microservices.

Authlib initializes verification as successful and performs zero signature checks, so a consumer that trusts the result can accept forged identity, authorization, inter-service or configuration claims.

Detail and 2 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Wednesday, September 30, 2026