CVE-2026-104056
N/A
N/A
Summary
Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values with attacker-controlled values rather than endpoint URLs that share the origin of the configured server metadata URL.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Authlib | Authlib | 1.7.2 | affected |
Weaknesses
- CWE-345 Insufficient Verification of Data Authenticity
- CWE-346 Origin Validation Error
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.