Описание
Security update for python-Authlib
This update for python-Authlib fixes the following issues
- CVE-2026-41425: Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth (bsc#1263114).
- CVE-2026-44681: Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's OpenIDImplicitGrant and OpenIDHybridGrant authorization endpoint exists (bsc#1266665).
Список пакетов
SUSE Linux Enterprise Module for Python 3 15 SP7
python311-Authlib-1.3.1-150600.3.22.1
Ссылки
- Link for SUSE-SU-2026:2968-1
- E-Mail link for SUSE-SU-2026:2968-1
- SUSE Security Ratings
- SUSE Bug 1263114
- SUSE Bug 1266665
- SUSE CVE CVE-2026-41425 page
- SUSE CVE CVE-2026-44681 page
Описание
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability is fixed in 1.6.11.
Затронутые продукты
SUSE Linux Enterprise Module for Python 3 15 SP7:python311-Authlib-1.3.1-150600.3.22.1
Ссылки
- CVE-2026-41425
- SUSE Bug 1263114
Описание
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's OpenIDImplicitGrant and OpenIDHybridGrant authorization endpoint lets a remote attacker cause the authorization server to issue an HTTP 302 to an attacker-chosen URL by submitting an authorization request that omits the openid scope. This vulnerability is fixed in 1.6.12 and 1.7.1.
Затронутые продукты
SUSE Linux Enterprise Module for Python 3 15 SP7:python311-Authlib-1.3.1-150600.3.22.1
Ссылки
- CVE-2026-44681
- SUSE Bug 1266665