Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104056

Quick assessment

Affected
Authlib Authlib
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Authlib 1.7.2 及以下版本存在一个漏洞:发现(discovery)JSON 元数据在缓存时未进行验证,也未与颁发者(issuer)来源绑定。这使得被污染的发现响应能够将所有端点值替换为攻击者控制的值,而非仅允许与已配置服务器元数据 URL 同源(origin)的端点 URL。

AI Predicted 8.1 Difficulty: Hard EPSS 0.10% · P1

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
Authlib Authlib 1.7.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104056

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
CVE-2026-104056
Source: CVE Program / CVE List V5
Vulnerability Description
Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values with attacker-controlled values rather than endpoint URLs that share the origin of the configured server metadata URL.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Authlib Authlib 1.7.2 -

II. Public POCs for CVE-2026-104056

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104056

请登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2026-104056

No comments yet


Leave a comment