Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41479

Опубликовано: 22 июн. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect when a request uses an unsupported response_type and supplies an attacker-controlled redirect_uri. The vulnerable behavior happens before client lookup and before any redirect URI validation. As a result, an attacker does not need a valid client registration, an authenticated user, or any prior state. A single request to the authorization endpoint is enough to obtain a 302 Location response to an arbitrary attacker-controlled URL. This vulnerability is fixed in 1.6.10 and 1.7.1.

A flaw was found in Authlib, a Python library for building OAuth and OpenID Connect servers. A remote attacker can exploit the OAuth 2.0 authorization endpoint by providing an unsupported response type and a malicious redirect Uniform Resource Identifier (URI). This allows the attacker to redirect users to arbitrary external websites, potentially leading to information disclosure or phishing attacks. The vulnerability does not require authentication or a valid client registration.

Отчет

Red Hat has assessed the impact of this vulnerability on Red Hat products. Products shipping Authlib 1.6.10 or later (1.6.x series) or 1.7.1 or later (1.7.x series) are not affected as they include the fix. Products shipping versions prior to 1.6.10 are affected at Moderate impact.

Меры по смягчению последствий

Upgrade Authlib to version 1.6.10 or later (for the 1.6.x series) or version 1.7.1 or later (for the 1.7.x series).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Fix deferred
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Not affected
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-agentic-sandbox-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-26/lightspeed-chatbot-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-27/lightspeed-chatbot-rhel9Fix deferred
Red Hat Enterprise Linux command line assistantrhel-cla/rhel-knowledge-bridge-rhel10Not affected
Red Hat Hardened ImagesjaegerNot affected
Red Hat OpenShift Virtualization 4container-native-virtualization/ocp-virt-validation-checkup-rhel9Not affected
Red Hat Quay 3quay/quay-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2491527authlib: Authlib: Open Redirect vulnerability via crafted authorization requests

EPSS

Процентиль: 8%
0.00183
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 2 месяцев назад

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect when a request uses an unsupported response_type and supplies an attacker-controlled redirect_uri. The vulnerable behavior happens before client lookup and before any redirect URI validation. As a result, an attacker does not need a valid client registration, an authenticated user, or any prior state. A single request to the authorization endpoint is enough to obtain a 302 Location response to an arbitrary attacker-controlled URL. This vulnerability is fixed in 1.6.10 and 1.7.1.

CVSS3: 5.4
nvd
около 2 месяцев назад

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect when a request uses an unsupported response_type and supplies an attacker-controlled redirect_uri. The vulnerable behavior happens before client lookup and before any redirect URI validation. As a result, an attacker does not need a valid client registration, an authenticated user, or any prior state. A single request to the authorization endpoint is enough to obtain a 302 Location response to an arbitrary attacker-controlled URL. This vulnerability is fixed in 1.6.10 and 1.7.1.

CVSS3: 5.4
debian
около 2 месяцев назад

Authlib is a Python library which builds OAuth and OpenID Connect serv ...

CVSS3: 5.4
redos
8 дней назад

Уязвимость python-authlib

CVSS3: 5.4
github
2 месяца назад

Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type

EPSS

Процентиль: 8%
0.00183
Низкий

5.4 Medium

CVSS3