MEDIUM SEVERITYCONFIRMED

OctKey.import_key(b"short") — 5-byte key accepted without warning for HS256

Package
authlib
Version
1.6.9
Verified
2026-03-28

Description

authlib's `OctKey.import_key()` accepts a 5-byte key for HS256 without any warning or error. The key is used to successfully encode, decode, and validate a JWT. RFC 7518 requires a minimum of 32 bytes for HS256.

Reproduction

from authlib.jose import jwt, OctKey
import time
key = OctKey.import_key(b'short')  # 5 bytes
token = jwt.encode({'alg': 'HS256'}, {'sub': 'admin', 'exp': int(time.time())+3600}, key)
claims = jwt.decode(token, key)
claims.validate()  # No error, no warning
← All bugsScan your code →