Authlib versions 1.7.2 and earlier contain a signature-verification bypass in JsonWebSignature.deserialize_json() when processing JSON Web Signature (JWS) general JSON serialization. A JWS object with an empty signatures array is accepted, and its payload is returned as successfully verified without signature validation or a cryptographic key. Applications that rely on this result to establish authenticity can accept attacker-controlled, unsigned payloads as trusted.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This three-file repository contains an MIT license, documentation, and a standalone Python proof of concept in exploit.py. The PoC imports Authlib's JsonWebSignature with HS256, first demonstrates normal valid-signature acceptance and wrong-key rejection, then constructs a General JSON JWS object whose payload encodes attacker-selected claims and whose signatures field is an empty array. It calls deserialize_json() with that object and reports success if Authlib returns the unsigned payload. The stated flaw is a vacuous-truth condition in Authlib's JSON JWS verification path: validity starts true and is only changed while iterating signature entries, so an empty list performs no verification. The code makes no network connections, writes no files, and invokes no remote endpoints; it is a local library-level demonstration. Practical exploitation depends on a service or application accepting externally supplied JSON JWS input and trusting the resulting payload.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical, remotely exploitable vulnerability with no required privileges or user interaction, affecting Ubuntu Linux 22.04 LTS, 24.04 LTS, and 26.04 LTS. The content does not provide the underlying technical flaw or affected component.
A signature-verification bypass in Authlib 1.7.2 and earlier: JsonWebSignature.deserialize_json() can treat a JSON Serialization JWS payload as verified without validating a signature or requiring a cryptographic key.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.