Loading
lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asymmetric public key. (This is similar to CVE-2022-29217 and CVE-2024-33663.)
Use CWE-347, Authlib vendor hub and Authlib product page to widen CVE-2024-37568 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-27962, CVE-2026-28490 and CVE-2026-28498 for nearby disclosures in the same product family.