Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

authlib — Vulnerabilities & Security Advisories 16

Browse all 16 CVE security advisories affecting authlib. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Authlib is an open-source OAuth and OpenID Connect framework primarily used for implementing authentication and authorization in applications. Historically, it has been susceptible to multiple remote code execution (RCE) vulnerabilities, cross-site scripting (XSS), and privilege escalation flaws, often stemming from improper input validation and insecure default configurations. The framework's 11 recorded CVEs highlight recurring issues in parameter handling and session management. While no major public security incidents have been documented, the consistent discovery of vulnerabilities suggests developers should implement strict input sanitization and maintain current library versions to mitigate potential exploitation risks.

Top products by authlib: authlib joserfc
CVE ID Title CVSS Severity Published
CVE-2026-62995 joserfc accepts JWT with padding, leading to JWT malleability — joserfc CWE-345 2.3 Low 2026-07-29
CVE-2026-49852 joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363) — joserfc CWE-287 - - 2026-07-17
CVE-2026-41479 Authlib OAuth 2.0 authorization endpoint open redirects to attacker-controlled redirect_uri on unsupported response_type — authlib CWE-601 5.4 Medium 2026-06-22
CVE-2026-48990 joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization — joserfc CWE-400 5.3 Medium 2026-06-17
CVE-2026-44681 Authlib: Open Redirect in Authlib OIDC Implicit/Hybrid Authorization — authlib CWE-601 6.1 Medium 2026-05-27
CVE-2026-41425 Authlib: Cross-site request forging when using cache — authlib CWE-352 5.4 Medium 2026-04-24
CVE-2026-28498 Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding — authlib CWE-354 8.2 High 2026-03-16
CVE-2026-28490 Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle — authlib CWE-203 - - 2026-03-16
CVE-2026-27962 Authlib JWS JWK Header Injection: Signature Verification Bypass — authlib CWE-347 9.1 Critical 2026-03-16
CVE-2026-28802 Authlib: Setting `alg: none` and a blank signature appears to bypass signature verification — authlib CWE-347 7.7 High 2026-03-06
CVE-2026-27932 joserfc PBES2 p2c Unbounded Iteration Count enables Denial of Service (DoS) — joserfc CWE-770 7.5 High 2026-03-03
CVE-2025-68158 Authlib: 1-click Account Takeover — authlib CWE-352 5.7 Medium 2026-01-08
CVE-2025-65015 joserfc has Possible Uncontrolled Resource Consumption Vulnerability Triggered by Logging Arbitrarily Large JWT Token Payloads — joserfc CWE-770 7.5AI High AI 2025-11-18
CVE-2025-62706 Authlib : JWE zip=DEF decompression bomb enables DoS — authlib CWE-400 6.5 Medium 2025-10-22
CVE-2025-61920 Authlib is vulnerable to Denial of Service via Oversized JOSE Segments — authlib CWE-20 7.5 High 2025-10-10
CVE-2025-59420 Authlib: JWS/JWT accepts unknown crit headers (RFC violation → possible authz bypass) — authlib CWE-345 7.5 High 2025-09-22

This page lists every published CVE security advisory associated with authlib. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.