Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 9

Количество 9

ubuntu логотип

CVE-2026-28498

5 месяцев назад

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (_verify_hash) responsible for validating the at_hash (Access Token Hash) and c_hash (Authorization Code Hash) claims exhibits a fail-open behavior when encountering an unsupported or unknown cryptographic algorithm. This flaw allows an attacker to bypass mandatory integrity protections by supplying a forged ID Token with a deliberately unrecognized alg header parameter. The library intercepts the unsupported state and silently returns True (validation passed), inherently violating fundamental cryptographic design principles and direct OIDC specifications. This issue has been patched in version 1.6.9.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-28498

5 месяцев назад

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (_verify_hash) responsible for validating the at_hash (Access Token Hash) and c_hash (Authorization Code Hash) claims exhibits a fail-open behavior when encountering an unsupported or unknown cryptographic algorithm. This flaw allows an attacker to bypass mandatory integrity protections by supplying a forged ID Token with a deliberately unrecognized alg header parameter. The library intercepts the unsupported state and silently returns True (validation passed), inherently violating fundamental cryptographic design principles and direct OIDC specifications. This issue has been patched in version 1.6.9.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2026-28498

5 месяцев назад

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (_verify_hash) responsible for validating the at_hash (Access Token Hash) and c_hash (Authorization Code Hash) claims exhibits a fail-open behavior when encountering an unsupported or unknown cryptographic algorithm. This flaw allows an attacker to bypass mandatory integrity protections by supplying a forged ID Token with a deliberately unrecognized alg header parameter. The library intercepts the unsupported state and silently returns True (validation passed), inherently violating fundamental cryptographic design principles and direct OIDC specifications. This issue has been patched in version 1.6.9.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-28498

5 месяцев назад

Authlib is a Python library which builds OAuth and OpenID Connect serv ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-m344-f55w-2m6j

5 месяцев назад

Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding

EPSS: Низкий
fstec логотип

BDU:2026-04354

5 месяцев назад

Уязвимость реализации JOSE библиотеки Authlib для серверов OAuth и OpenID Connect, связанная с неправильной проверкой значения целостности, позволяющая нарушителю обойти существующие механизмы безопасности

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260417-73-0030

4 месяца назад

Уязвимость python-authlib

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20392-1

5 месяцев назад

Security update for python-Authlib

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0975-1

5 месяцев назад

Security update for python-Authlib

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-28498

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (_verify_hash) responsible for validating the at_hash (Access Token Hash) and c_hash (Authorization Code Hash) claims exhibits a fail-open behavior when encountering an unsupported or unknown cryptographic algorithm. This flaw allows an attacker to bypass mandatory integrity protections by supplying a forged ID Token with a deliberately unrecognized alg header parameter. The library intercepts the unsupported state and silently returns True (validation passed), inherently violating fundamental cryptographic design principles and direct OIDC specifications. This issue has been patched in version 1.6.9.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
redhat логотип
CVE-2026-28498

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (_verify_hash) responsible for validating the at_hash (Access Token Hash) and c_hash (Authorization Code Hash) claims exhibits a fail-open behavior when encountering an unsupported or unknown cryptographic algorithm. This flaw allows an attacker to bypass mandatory integrity protections by supplying a forged ID Token with a deliberately unrecognized alg header parameter. The library intercepts the unsupported state and silently returns True (validation passed), inherently violating fundamental cryptographic design principles and direct OIDC specifications. This issue has been patched in version 1.6.9.

CVSS3: 9.1
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2026-28498

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (_verify_hash) responsible for validating the at_hash (Access Token Hash) and c_hash (Authorization Code Hash) claims exhibits a fail-open behavior when encountering an unsupported or unknown cryptographic algorithm. This flaw allows an attacker to bypass mandatory integrity protections by supplying a forged ID Token with a deliberately unrecognized alg header parameter. The library intercepts the unsupported state and silently returns True (validation passed), inherently violating fundamental cryptographic design principles and direct OIDC specifications. This issue has been patched in version 1.6.9.

CVSS3: 7.5
0%
Низкий
5 месяцев назад
debian логотип
CVE-2026-28498

Authlib is a Python library which builds OAuth and OpenID Connect serv ...

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-m344-f55w-2m6j

Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding

0%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-04354

Уязвимость реализации JOSE библиотеки Authlib для серверов OAuth и OpenID Connect, связанная с неправильной проверкой значения целостности, позволяющая нарушителю обойти существующие механизмы безопасности

CVSS3: 7.5
0%
Низкий
5 месяцев назад
redos логотип
ROS-20260417-73-0030

Уязвимость python-authlib

CVSS3: 7.5
0%
Низкий
4 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20392-1

Security update for python-Authlib

5 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:0975-1

Security update for python-Authlib

5 месяцев назад

Уязвимостей на страницу