CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-28490

unknowncovered by 1 sourcefirst seen 2026-07-16
Jay Neiva and Mauro Carrillo discovered that Authlib did not properly validate cryptographic keys embedded in JWT headers. An attacker could possibly use this issue to forge trusted tokens, resulting in authentication and authorization bypass. (CVE-2026-27962) Jay Neiva and Mauro Carrillo discovered that Authlib incorrectly handled RSA1_5 encrypted tokens. An attacker could possibly use this issue to recover sensitive encrypted information, resulting in information disclosure. (CVE-2026-28490) Jay Neiva and Mauro Carrillo discovered that Authlib did not properly reject unsupported cryptographic algorithms when validating OpenID Connect ID tokens. An attacker could possibly use this issue to bypass token integrity checks, resulting in authentication bypass. (CVE-2026-28498) Johnny Deuss discovered that Authlib did not provide cross-site request forgery protection for the OAuth cache feature in its Starlette integration. An attacker could possibly use this issue to perform unauthorized OAuth actions, resulting in cross-site request forgery. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-41425)

CSIRTS triage

What
Multiple vulnerabilities in Authlib could allow attackers to forge tokens and bypass authentication.
Who is affected
Users of Authlib.
Urgency
Remediation is important to mitigate risks of token forgery and information disclosure.
Action
Review and apply updates as necessary.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-28490

Get an email if CVE-2026-28490 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-28490

CVE.org record

Embed the live status

CVE-2026-28490 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-28490 status](https://www.csirts.com/badge/CVE-2026-28490)](https://www.csirts.com/cve/CVE-2026-28490)