CVE-2026-28802: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-28802 is a JWT signature verification bypass vulnerability in the Python Authlib library, allowing attackers to forge JWTs using the alg: none algorithm with an empty signature. The flaw affects Authlib versions 1.6.5 and 1.6.6, introduced by commit a61c2ac which added support for the JWS none algorithm without enforcing a secure-by-default rejection policy. It was disclosed on March 4, 2026, and patched in version 1.6.7. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 7.7 (High) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-347 (Improper Verification of Cryptographic Signature). The vulnerability was introduced in commit a61c2ac, which changed the verify() method of the NoneAlgorithm class from always returning False to returning True when the signature is an empty byte string (sig == b""). This caused the default jwt instance to include none in its algorithm registry, meaning any JWT presenting alg: none with a blank signature would pass verification without any cryptographic check. An unauthenticated remote attacker can craft a JWT with arbitrary claims (e.g., role: admin), set the header to {"alg": "none"}, and append an empty signature segment — no valid key or secret is required (GitHub Advisory, Commit a61c2ac).

Impact

Successful exploitation allows an unauthenticated attacker to forge arbitrary JWT tokens accepted by any application using Authlib 1.6.5–1.6.6 for authentication or authorization. This can lead to complete authentication bypass, privilege escalation (e.g., claiming admin roles), unauthorized access to protected resources, and unauthorized modification of application data. The impact is particularly severe in OAuth2 and OpenID Connect deployments where JWTs govern identity and access control decisions (GitHub Advisory, Red Hat Bugzilla).

Exploitability

A proof-of-concept (PoC) is publicly available in the official GitHub Security Advisory, demonstrating that installing authlib==1.6.5 and submitting a forged alg: none token results in successful verification with the output VULNERABLE: Forged token (alg:none) accepted: role=admin. The CVSS v4.0 exploit maturity is rated PROOF_OF_CONCEPT. The EPSS score is approximately 0.019–0.027%, indicating low current exploitation probability. No in-the-wild exploitation or threat actor attribution has been reported, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).

Exploitation steps

  1. Identify target: Locate applications using Authlib versions 1.6.5 or 1.6.6 for JWT-based authentication or authorization (e.g., OAuth2/OIDC endpoints).
  2. Craft forged JWT header: Create a JWT header specifying {"alg": "none"} and Base64url-encode it (without padding).
  3. Craft malicious payload: Build a JWT payload with desired claims, such as {"sub": "user123", "role": "admin", "iat": <timestamp>}, and Base64url-encode it.
  4. Assemble the token: Concatenate the encoded header, encoded payload, and an empty signature segment: <header_b64>.<payload_b64>. (note the trailing dot with no signature).
  5. Submit the forged token: Send the crafted JWT to the target application's authenticated endpoint (e.g., in the Authorization: Bearer <token> header).
  6. Achieve unauthorized access: The vulnerable Authlib jwt.decode() call accepts the token without cryptographic verification, granting the attacker the privileges specified in the forged payload (GitHub Advisory).

Indicators of compromise

  • Network: Incoming HTTP requests with Authorization: Bearer tokens where the JWT header decodes to {"alg": "none"}; JWT tokens with only two dots and an empty third segment (e.g., eyJ...eyJ....).
  • Logs: Application access logs showing successful authentication events for users with elevated roles (e.g., admin) from unexpected sources or at unusual times; JWT decode operations succeeding without a corresponding valid key lookup.
  • Application Behavior: Unexpected privilege escalation events; users accessing resources beyond their assigned permissions; anomalous API calls consistent with admin-level access from non-admin accounts.

Mitigation and workarounds

Upgrade Authlib to version 1.6.7 or later, which removes none from the default JWT algorithm registry (commit b87c32e). The fix explicitly enumerates only cryptographic algorithms (HS256, RS256, ES256, PS256, etc.) in the default jwt instance, preventing alg: none tokens from being accepted without explicit opt-in. As an interim workaround for applications that cannot immediately upgrade, developers should validate the alg header claim before processing and reject any token specifying alg: none. IBM watsonx Orchestrate with watsonx Assistant Cartridge is also affected and has a separate advisory (GitHub Advisory, Commit b87c32e, IBM Advisory).

Community reactions

The vulnerability was reported by researcher michael-guignard and published by Authlib maintainer lepture on March 4, 2026. Red Hat tracked the issue as high severity in Bugzilla with 35 CC'd users, indicating broad interest across enterprise Linux distributions. The issue was also covered by security blogs and PoC roundups, including a mention in a weekly PoC digest (Red Hat Bugzilla, GitHub Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

python-authlib

Fixed

sid

python-authlib: 1.6.7-1

Fixed

trixie

python-authlib

Affected

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management