CVE-2026-104056
- EPSS 0.1%
- Veröffentlicht 01.10.2026 18:03:27
- Zuletzt bearbeitet 05.10.2026 19:17:14
Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values with attacker-controlled values rat...
CVE-2026-96760
- EPSS 0.13%
- Veröffentlicht 28.09.2026 20:17:11
- Zuletzt bearbeitet 01.10.2026 14:17:32
Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for a signatur...
CVE-2026-41479
- EPSS 0.18%
- Veröffentlicht 22.06.2026 20:35:13
- Zuletzt bearbeitet 26.06.2026 20:10:38
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect when a request uses an unsupported response_type and ...
CVE-2026-44681
- EPSS 0.25%
- Veröffentlicht 27.05.2026 19:20:44
- Zuletzt bearbeitet 02.06.2026 17:16:32
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's OpenIDImplicitGrant and OpenIDHybridGrant authorization endpoint lets a remote attacker cause the auth...
CVE-2026-41425
- EPSS 0.11%
- Veröffentlicht 24.04.2026 19:14:37
- Zuletzt bearbeitet 28.04.2026 18:18:26
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability is fixed in 1.6.11.
CVE-2026-28498
- EPSS 0.23%
- Veröffentlicht 16.03.2026 18:16:07
- Zuletzt bearbeitet 10.09.2026 13:18:01
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, ...
CVE-2026-28490
- EPSS 0.14%
- Veröffentlicht 16.03.2026 17:37:57
- Zuletzt bearbeitet 17.03.2026 20:45:45
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a cryptographic padding oracle vulnerability was identified in the Authlib Python library concerning the implementation of the JSON Web Encryption (JWE...
CVE-2026-27962
- EPSS 0.55%
- Veröffentlicht 16.03.2026 17:34:38
- Zuletzt bearbeitet 10.09.2026 13:18:01
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an unauthenticated attacker to forge arbitrary JWT tokens that pass signatu...
CVE-2026-28802
- EPSS 0.43%
- Veröffentlicht 06.03.2026 06:44:26
- Zuletzt bearbeitet 10.09.2026 13:18:02
Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing alg: none and an empty signature was passing the signature verification...
CVE-2025-68158
- EPSS 0.25%
- Veröffentlicht 08.01.2026 17:58:17
- Zuletzt bearbeitet 30.03.2026 13:16:21
Authlib is a Python library which builds OAuth and OpenID Connect servers. In versions 1.0.0 through 1.6.5, cache-backed state/request-token storage is not tied to the initiating user session, so CSRF is possible for any attacker that has a valid sta...