CVE-2026-27962 is a critical JWK Header Injection vulnerability in Authlib, a Python library for OAuth and OpenID Connect servers, affecting versions prior to 1.6.9. This flaw allows unauthenticated attackers to forge arbitrary JWT tokens by embedding their public key in the header, thereby bypassing signature verification. Rated 9.1 Critical (CVSS:3.1/AV:N/AC:L/PR:N), it enables a complete bypass of authentication and authorization due to its network-exploitable, low-complexity nature with no privileges or user interaction required. Although no public exploit code is currently available on common platforms like Metasploit or ExploitDB, the CVE is listed on the "Hot List: Active," indicating significant attention and potential for exploitation, further evidenced by community discussion and media coverage. The issue has been patched in version 1.6.9.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.9CPE matchmatch criteria | cpe:2.3:a:authlib:authlib:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.