Broken Keys: Critical Authlib Flaws Expose Millions to JWT Forgery and Padding Oracles
ID: 1d4ae97b-c37a-525b-9371-67da53827642
STIX ID: report--1d4ae97b-c37a-525b-9371-67da53827642
Feed Name: securityonline.info
Security researchers disclosed three critical vulnerabilities in Authlib (affecting all versions up to 1.6.8) that together allow padding-oracle decryption of RSA1_5-encrypted data, silent acceptance of ID Tokens with unrecognized algorithms, and a key=None signature verification bypass enabling arbitrary JWT forgery and authentication/authorization bypass; maintainers advise immediate upgrade to Authlib 1.6.9+, auditing token verification key sources, and migrating away from RSA1_5 where possible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
