Skip to content

Authlib JWS JWK Header Injection: Signature Verification Bypass

Critical severity GitHub Reviewed Published Mar 15, 2026 in authlib/authlib • Updated Mar 16, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts