CVE-2026-28802 | Authlib up to 1.6.6 JWT signature verification (GHSA-7wc2-qxgw-g8gg / Nessus ID 301403)
A vulnerability described as problematic has been identified in Authlib up to 1.6.6. The affected element is an unknown function of the component JWT Handler. The manipulation results in improper verification of cryptographic signature.
This vulnerability is known as CVE-2026-28802. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.