Products: 2
    Vulnerabilities: 18
    Known Exploited: 0
    2
    Critical Level Threats
    6
    High Level Threats
    9
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-75509

    joserfc claim-validation bypass via array-typed single-string claims (iss/sub/jti)

    Last Modified: Aug 25, 2026
    Published: Aug 24, 2026

    CVE-2026-62995

    joserfc accepts JWT with padding, leading to JWT malleability

    Last Modified: Jul 30, 2026
    Published: Jul 29, 2026

    CVE-2026-49852

    joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)

    Last Modified: Jul 20, 2026
    Published: Jul 17, 2026

    CVE-2026-41479

    Authlib OAuth 2.0 authorization endpoint open redirects to attacker-controlled redirect_uri on unsupported response_type

    Last Modified: Jun 23, 2026
    Published: Jun 22, 2026

    CVE-2026-48990

    joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization

    Last Modified: Jun 18, 2026
    Published: Jun 17, 2026
    Items Per Page
    Authlib Vulnerabilities & Security CVEs | CVE-DB