Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41425

Опубликовано: 24 апр. 2026
Источник: redhat
CVSS3: 5.4

Описание

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability is fixed in 1.6.11.

A flaw was found in Authlib, a Python library for building OAuth and OpenID Connect servers. A remote attacker could exploit a missing Cross-Site Request Forgery (CSRF) protection on the cache feature within authlib.integrations.starlette_client.OAuth. This vulnerability allows an attacker to trick an authenticated user into performing unintended actions, potentially leading to unauthorized information disclosure or data manipulation.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-chatbot-rhel9Fix deferred
Red Hat Quay 3quay/quay-rhel8Fix deferred
Red Hat Quay 3quay/quay-rhel9Fix deferred
Red Hat Satellite 6satellite/foreman-mcp-server-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-807
https://bugzilla.redhat.com/show_bug.cgi?id=2461690authlib: Authlib: Cross-Site Request Forgery (CSRF) vulnerability in OAuth cache feature

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
4 месяца назад

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability is fixed in 1.6.11.

CVSS3: 5.4
nvd
4 месяца назад

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability is fixed in 1.6.11.

CVSS3: 5.4
debian
4 месяца назад

Authlib is a Python library which builds OAuth and OpenID Connect serv ...

CVSS3: 5.4
github
4 месяца назад

Authlib: Cross-site request forging when using cache

5.4 Medium

CVSS3