Skip to content

chore: bump authlib to 1.6.7 for CVE-2026-28802#95

Merged
jtroup merged 1 commit intostacklet/integrationfrom
elmo/security-treadmill
Mar 12, 2026
Merged

chore: bump authlib to 1.6.7 for CVE-2026-28802#95
jtroup merged 1 commit intostacklet/integrationfrom
elmo/security-treadmill

Conversation

@jtroup
Copy link

@jtroup jtroup commented Mar 6, 2026

what

Bump authlib from 1.6.6 to 1.6.7.

why

authlib 1.6.6 is vulnerable to CVE-2026-28802 (CVSS 7.5 HIGH): JWTs with
alg: none and an empty signature bypass signature verification. 1.6.7
fixes this.

testing

Existing test suite; no logic changes in this repo.

docs

No docs changes required.

@jtroup jtroup merged commit 82179b1 into stacklet/integration Mar 12, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants