<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:50:21.840148+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-04352</id>
    <title>bdu:2026-04352</title>
    <updated>2026-10-02T19:50:22.239804+00:00</updated>
    <content>bdu:2026-04352</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-04352"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-fastmcp-cve-2026-27962</id>
    <title>BREW-fastmcp-CVE-2026-27962 — Authlib JWS JWK Header Injection: Signature Verification Bypass</title>
    <updated>2026-10-02T19:50:22.239849+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: fastmcp</p>
<p>## Description</p>
<p>### Summary</p>
<p>A JWK Header Injection vulnerability in `authlib`'s JWS implementation allows an unauthenticated
attacker to forge arbitrary JWT tokens that pass signature verification. When `key=None` is passed
to any JWS deserialization function, the library extracts and uses the cryptographic key embedded
in the attacker-controlled JWT `jwk` header field. An attacker can sign a token with their own
private key, embed the matching public key in the header, and have the server accept the forged
token as cryptographically valid — bypassing authentication and authorization entirely.</p>
<p>This behavior violates **RFC 7515 §4.1.3** and the validation algorithm defined in **RFC 7515 §5.2**.</p>
<p>### Details</p>
<p>**Vulnerable file:** `authlib/jose/rfc7515/jws.py`  
**Vulnerable method:** `JsonWebSignature._prepare_algorithm_key()`  
**Lines:** 272–273</p>
<p>```python
elif key is None and "jwk" in header:
    key = header["jwk"]   # ← attacker-controlled key used for verification
```</p>
<p>When `key=None` is passed to `jws.deserialize_compact()`, `jws.deserialize_json()`, or
`jws.deserialize()`, the library checks the JWT header for a `jwk` field. If present, it extracts
that value — which is fully attacker-controlled — and uses it as the verification key.</p>
<p>**RFC 7515 violations:**</p>
<p>- **§4.1.3** explicitly states the `jwk` header parameter is **"NOT RECOMMENDED"** because keys
  embedded by the token submitter cannot be trusted as a verification anchor.
- **§5.2 (Validation Algorithm)** sp…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-fastmcp-cve-2026-27962"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366096</id>
    <title>EUVD-2026-366096</title>
    <updated>2026-10-02T19:50:22.239926+00:00</updated>
    <content>EUVD-2026-366096</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366096"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-27962</id>
    <title>fkie_cve-2026-27962</title>
    <updated>2026-10-02T19:50:22.239942+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrary JWT tokens that pass signature verification. When key=None is passed to any JWS deserialization function, the library extracts and uses the cryptographic key embedded in the attacker-controlled JWT jwk header field. An attacker can sign a token with their own private key, embed the matching public key in the header, and have the server accept the forged token as cryptographically valid — bypassing authentication and authorization entirely. This issue has been patched in version 1.6.9.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-27962"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-wvwj-cvrp-7pv5</id>
    <title>GHSA-wvwj-cvrp-7pv5 — Authlib JWS JWK Header Injection: Signature Verification Bypass</title>
    <updated>2026-10-02T19:50:22.239971+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: authlib</p>
<p>## Description</p>
<p>### Summary</p>
<p>A JWK Header Injection vulnerability in `authlib`'s JWS implementation allows an unauthenticated
attacker to forge arbitrary JWT tokens that pass signature verification. When `key=None` is passed
to any JWS deserialization function, the library extracts and uses the cryptographic key embedded
in the attacker-controlled JWT `jwk` header field. An attacker can sign a token with their own
private key, embed the matching public key in the header, and have the server accept the forged
token as cryptographically valid — bypassing authentication and authorization entirely.</p>
<p>This behavior violates **RFC 7515 §4.1.3** and the validation algorithm defined in **RFC 7515 §5.2**.</p>
<p>### Details</p>
<p>**Vulnerable file:** `authlib/jose/rfc7515/jws.py`  
**Vulnerable method:** `JsonWebSignature._prepare_algorithm_key()`  
**Lines:** 272–273</p>
<p>```python
elif key is None and "jwk" in header:
    key = header["jwk"]   # ← attacker-controlled key used for verification
```</p>
<p>When `key=None` is passed to `jws.deserialize_compact()`, `jws.deserialize_json()`, or
`jws.deserialize()`, the library checks the JWT header for a `jwk` field. If present, it extracts
that value — which is fully attacker-controlled — and uses it as the verification key.</p>
<p>**RFC 7515 violations:**</p>
<p>- **§4.1.3** explicitly states the `jwk` header parameter is **"NOT RECOMMENDED"** because keys
  embedded by the token submitter cannot be trusted as a verification anchor.
- **§5.2 (Validation Algorithm)** sp…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-wvwj-cvrp-7pv5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20392-1</id>
    <title>openSUSE-SU-2026:20392-1 — Security update for python-Authlib</title>
    <updated>2026-10-02T19:50:22.240030+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-Authlib</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:20392-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-287</id>
    <title>PYSEC-2026-287 — Authlib JWS JWK Header Injection: Signature Verification Bypass</title>
    <updated>2026-10-02T19:50:22.240050+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: authlib</p>
<p>## Description</p>
<p>### Summary</p>
<p>A JWK Header Injection vulnerability in `authlib`'s JWS implementation allows an unauthenticated
attacker to forge arbitrary JWT tokens that pass signature verification. When `key=None` is passed
to any JWS deserialization function, the library extracts and uses the cryptographic key embedded
 in the attacker-controlled JWT `jwk` header field. An attacker can sign a token with their own
private key, embed the matching public key in the header, and have the server accept the forged
token as cryptographically valid — bypassing authentication and authorization entirely.</p>
<p>This behavior violates **RFC 7515 §4.1.3** and the validation algorithm defined in **RFC 7515 §5.2**.</p>
<p>### Details</p>
<p>**Vulnerable file:** `authlib/jose/rfc7515/jws.py`  
**Vulnerable method:** `JsonWebSignature._prepare_algorithm_key()`  
**Lines:** 272–273</p>
<p>```python
elif key is None and "jwk" in header:
    key = header["jwk"]   # ← attacker-controlled key used for verification
 ```</p>
<p>When `key=None` is passed to `jws.deserialize_compact()`, `jws.deserialize_json()`, or
`jws.deserialize()`, the library checks the JWT header for a `jwk` field. If present, it extracts
that value — which is fully attacker-controlled — and uses it as the verification key.</p>
<p>**RFC 7515 violations:**</p>
<p>- **§4.1.3** explicitly states the `jwk` header parameter is **"NOT RECOMMENDED"** because keys
  embedded by the token submitter cannot be trusted as a verification anchor.
- **§5.2 (Validation Algorithm)**…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-287"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:19375</id>
    <title>RHSA-2026:19375 — Red Hat Security Advisory: Red Hat Quay 3.16.4</title>
    <updated>2026-10-02T19:50:22.240106+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: net/url: Memory exhaustion in query parameter parsing in net/url axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization mirror-registry: quay: quay: Server-Side Request Forgery via log export functionality jsrsasign: jsrsasign: Denial of Service via infinite loop in bnModInverse function with crafted inputs jsrsasign: jsrsasign: Private key recovery via incomplete comparison checks biasing DSA nonces jsrsasign: jsrsasign: Cryptographic signature forgery via malicious DSA domain parameters jsrsasign: jsrsasign: Private Key Recovery via Missing Cryptographic Step in DSA Signing jsrsasign: jsrsasign: Signature verification bypass via negative exponent handling net/url: Incorrect parsing of IPv6 host literals in net/url crypto/x509: Incorrect enforcement of email constraints in crypto/x509 pyOpenSSL: DTLS cookie callback buffer overflow authlib: Authlib: Authentication bypass due to JWK Header Injection vulnerability authlib: Authlib: Signature verification bypass via malicious JWT allows unauthorized access immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution svgo: SVGO: Denial of Service via XML entity expansion pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root github.com/jackc/pgproto3/v2: github.com/jackc/p…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:19375"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27962</id>
    <title>UBUNTU-CVE-2026-27962</title>
    <updated>2026-10-02T19:50:22.240183+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:22.04:LTS: python-authlib, Ubuntu:Pro:24.04:LTS: python-authlib, Ubuntu:25.10: python-authlib, Ubuntu:Pro:26.04:LTS: python-authlib</p>
<p>Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrary JWT tokens that pass signature verification. When key=None is passed to any JWS deserialization function, the library extracts and uses the cryptographic key embedded in the attacker-controlled JWT jwk header field. An attacker can sign a token with their own private key, embed the matching public key in the header, and have the server accept the forged token as cryptographically valid — bypassing authentication and authorization entirely. This issue has been patched in version 1.6.9.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-27962"/>
  </entry>
</feed>
