
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28802 is a JWT signature verification bypass vulnerability in the Python Authlib library, allowing attackers to forge JWTs using the alg: none algorithm with an empty signature. The flaw affects Authlib versions 1.6.5 and 1.6.6, introduced by commit a61c2ac which added support for the JWS none algorithm without enforcing a secure-by-default rejection policy. It was disclosed on March 4, 2026, and patched in version 1.6.7. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) and a CVSS v4.0 base score of 7.7 (High) (GitHub Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-347 (Improper Verification of Cryptographic Signature). The vulnerability was introduced in commit a61c2ac, which changed the verify() method of the NoneAlgorithm class from always returning False to returning True when the signature is an empty byte string (sig == b""). This caused the default jwt instance to include none in its algorithm registry, meaning any JWT presenting alg: none with a blank signature would pass verification without any cryptographic check. An unauthenticated remote attacker can craft a JWT with arbitrary claims (e.g., role: admin), set the header to {"alg": "none"}, and append an empty signature segment — no valid key or secret is required (GitHub Advisory, Commit a61c2ac).
Successful exploitation allows an unauthenticated attacker to forge arbitrary JWT tokens accepted by any application using Authlib 1.6.5–1.6.6 for authentication or authorization. This can lead to complete authentication bypass, privilege escalation (e.g., claiming admin roles), unauthorized access to protected resources, and unauthorized modification of application data. The impact is particularly severe in OAuth2 and OpenID Connect deployments where JWTs govern identity and access control decisions (GitHub Advisory, Red Hat Bugzilla).
A proof-of-concept (PoC) is publicly available in the official GitHub Security Advisory, demonstrating that installing authlib==1.6.5 and submitting a forged alg: none token results in successful verification with the output VULNERABLE: Forged token (alg:none) accepted: role=admin. The CVSS v4.0 exploit maturity is rated PROOF_OF_CONCEPT. The EPSS score is approximately 0.019–0.027%, indicating low current exploitation probability. No in-the-wild exploitation or threat actor attribution has been reported, and the vulnerability is not listed in the CISA KEV catalog (GitHub Advisory).
{"alg": "none"} and Base64url-encode it (without padding).{"sub": "user123", "role": "admin", "iat": <timestamp>}, and Base64url-encode it.<header_b64>.<payload_b64>. (note the trailing dot with no signature).Authorization: Bearer <token> header).jwt.decode() call accepts the token without cryptographic verification, granting the attacker the privileges specified in the forged payload (GitHub Advisory).Authorization: Bearer tokens where the JWT header decodes to {"alg": "none"}; JWT tokens with only two dots and an empty third segment (e.g., eyJ...eyJ....).admin) from unexpected sources or at unusual times; JWT decode operations succeeding without a corresponding valid key lookup.Upgrade Authlib to version 1.6.7 or later, which removes none from the default JWT algorithm registry (commit b87c32e). The fix explicitly enumerates only cryptographic algorithms (HS256, RS256, ES256, PS256, etc.) in the default jwt instance, preventing alg: none tokens from being accepted without explicit opt-in. As an interim workaround for applications that cannot immediately upgrade, developers should validate the alg header claim before processing and reject any token specifying alg: none. IBM watsonx Orchestrate with watsonx Assistant Cartridge is also affected and has a separate advisory (GitHub Advisory, Commit b87c32e, IBM Advisory).
The vulnerability was reported by researcher michael-guignard and published by Authlib maintainer lepture on March 4, 2026. Red Hat tracked the issue as high severity in Bugzilla with 35 CC'd users, indicating broad interest across enterprise Linux distributions. The issue was also covered by security blogs and PoC roundups, including a mention in a weekly PoC digest (Red Hat Bugzilla, GitHub Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."