logo

Broken Keys: Critical Authlib Flaws Expose Millions to JWT Forgery and Padding Oracles

ID: 1d4ae97b-c37a-525b-9371-67da53827642

STIX ID: report--1d4ae97b-c37a-525b-9371-67da53827642

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-03-17

Date Updated: 2026-04-23

Author: Ddos

...
...

Security researchers disclosed three critical vulnerabilities in Authlib (affecting all versions up to 1.6.8) that together allow padding-oracle decryption of RSA1_5-encrypted data, silent acceptance of ID Tokens with unrecognized algorithms, and a key=None signature verification bypass enabling arbitrary JWT forgery and authentication/authorization bypass; maintainers advise immediate upgrade to Authlib 1.6.9+, auditing token verification key sources, and migrating away from RSA1_5 where possible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.