# CVE-2026-49852

## Summary

- **CVE ID:** CVE-2026-49852
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-287, CWE-326, CWE-1391
- **Published:** Jul 17, 2026
- **Last Modified:** Jul 20, 2026

## Description

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. Prior to 1.6.8, joserfc.jwt.decode accepts attacker-forged HMAC-signed tokens when the caller-supplied verification key is the empty string or None, because HMACAlgorithm.sign and HMACAlgorithm.verify in src/joserfc/_rfc7518/jws_algs.py pass the output of OctKey.get_op_key(...) to hmac.new(...) and OctKey.import_key in src/joserfc/_rfc7518/oct_key.py only emits a SecurityWarning for keys shorter than 14 bytes without rejecting zero-length input. This issue is fixed in version 1.6.8.

## Affected Products

- authlib — joserfc (< 1.6.8)

## References

- [CNA](https://github.com/authlib/joserfc/security/advisories/GHSA-gg9x-qcx2-xmrh)
- [CNA](https://github.com/authlib/joserfc/commit/86d00910b2b2d2d07503fee9b572906daefab7f1)
- [CNA](https://github.com/authlib/joserfc/releases/tag/1.6.8)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.19%
- **EPSS Percentile:** 9.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._