Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-27962

35
FAUCET Score

CVE-2026-27962 is a critical JWK Header Injection vulnerability in Authlib, a Python library for OAuth and OpenID Connect servers, affecting versions prior to 1.6.9. This flaw allows unauthenticated attackers to forge arbitrary JWT tokens by embedding their public key in the header, thereby bypassing signature verification. Rated 9.1 Critical (CVSS:3.1/AV:N/AC:L/PR:N), it enables a complete bypass of authentication and authorization due to its network-exploitable, low-complexity nature with no privileges or user interaction required. Although no public exploit code is currently available on common platforms like Metasploit or ExploitDB, the CVE is listed on the "Hot List: Active," indicating significant attention and potential for exploitation, further evidenced by community discussion and media coverage. The issue has been patched in version 1.6.9.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.6.9CPE matchmatch criteria
cpe:2.3:a:authlib:authlib:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.55%
Probability of exploitation in next 30 days
EPSS Percentile
42.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0055 is in the 22nd percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: authlibFixed in: 1.6.9
ubuntupatch availablevia ubuntu_usn
Product: python-authlib (jammy)Fixed in: 0.15.5-1ubuntu0.1~esm2
ubuntupatch availablevia ubuntu_usn
Product: python-authlib (noble)Fixed in: 1.3.0-1ubuntu0.1~esm2
ubuntupatch availablevia ubuntu_usn
Product: python-authlib (resolute)Fixed in: 1.6.7-1ubuntu0.1~esm1

Vendor Advisories (2)

ubuntuUSN-8557-1

Authlib vulnerabilities

Jul 16, 2026
pipGHSA-wvwj-cvrp-7pv5critical

Authlib JWS JWK Header Injection: Signature Verification Bypass

Mar 16, 2026

References

access.redhat.com / errata/RHSA-2026:19375
access.redhat.com / errata/RHSA-2026:24853
access.redhat.com / errata/RHSA-2026:5665
access.redhat.com / errata/RHSA-2026:7314
access.redhat.com / security/cve/CVE-2026-27962
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-27962.json
github.com / authlib/authlib/commit/a5d4b2d4c9e46bfa11c82f85fdc2bcc0b50ae681
Patch
github.com / authlib/authlib/releases/tag/v1.6.9
ProductRelease Notes
github.com / authlib/authlib/security/advisories/GHSA-wvwj-cvrp-7pv5
ExploitMitigationVendor Advisory