Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2026-44681

3 месяца назад

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's OpenIDImplicitGrant and OpenIDHybridGrant authorization endpoint lets a remote attacker cause the authorization server to issue an HTTP 302 to an attacker-chosen URL by submitting an authorization request that omits the openid scope. This vulnerability is fixed in 1.6.12 and 1.7.1.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2026-44681

3 месяца назад

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's OpenIDImplicitGrant and OpenIDHybridGrant authorization endpoint lets a remote attacker cause the authorization server to issue an HTTP 302 to an attacker-chosen URL by submitting an authorization request that omits the openid scope. This vulnerability is fixed in 1.6.12 and 1.7.1.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2026-44681

3 месяца назад

Authlib is a Python library which builds OAuth and OpenID Connect serv ...

CVSS3: 6.1
EPSS: Низкий
redos логотип

ROS-20260810-73-0036

4 дня назад

Уязвимость python-authlib

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-r95x-qfjj-fjj2

3 месяца назад

Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect

CVSS3: 6.1
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2968-1

около 1 месяца назад

Security update for python-Authlib

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-44681

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's OpenIDImplicitGrant and OpenIDHybridGrant authorization endpoint lets a remote attacker cause the authorization server to issue an HTTP 302 to an attacker-chosen URL by submitting an authorization request that omits the openid scope. This vulnerability is fixed in 1.6.12 and 1.7.1.

CVSS3: 6.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-44681

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's OpenIDImplicitGrant and OpenIDHybridGrant authorization endpoint lets a remote attacker cause the authorization server to issue an HTTP 302 to an attacker-chosen URL by submitting an authorization request that omits the openid scope. This vulnerability is fixed in 1.6.12 and 1.7.1.

CVSS3: 6.1
0%
Низкий
3 месяца назад
debian логотип
CVE-2026-44681

Authlib is a Python library which builds OAuth and OpenID Connect serv ...

CVSS3: 6.1
0%
Низкий
3 месяца назад
redos логотип
ROS-20260810-73-0036

Уязвимость python-authlib

CVSS3: 6.1
0%
Низкий
4 дня назад
github логотип
GHSA-r95x-qfjj-fjj2

Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect

CVSS3: 6.1
0%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2968-1

Security update for python-Authlib

около 1 месяца назад

Уязвимостей на страницу