Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-41425

Опубликовано: 24 апр. 2026
Источник: debian

Описание

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability is fixed in 1.6.11.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-authlibfixed1.7.0-1package
python-authlibfixed1.2.0-1+deb12u2bookwormpackage
python-authlibnot-affectedbullseyepackage

Примечания

  • https://github.com/authlib/authlib/security/advisories/GHSA-jj8c-mmj3-mmgv

  • Fixed by: https://github.com/authlib/authlib/commit/401a7709c3fe43bce1b2105d16a475b688faa788 (v1.6.11)

Связанные уязвимости

CVSS3: 5.4
ubuntu
4 месяца назад

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability is fixed in 1.6.11.

CVSS3: 5.4
redhat
4 месяца назад

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability is fixed in 1.6.11.

CVSS3: 5.4
nvd
4 месяца назад

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability is fixed in 1.6.11.

CVSS3: 5.4
github
4 месяца назад

Authlib: Cross-site request forging when using cache

suse-cvrf
28 дней назад

Security update for python-Authlib