Search CVE reports


Toggle filters

1 – 5 of 5 results


CVE-2025-68158

Medium priority
Needs evaluation

Authlib is a Python library which builds OAuth and OpenID Connect servers. In version 1.6.5 and prior, cache-backed state/request-token storage is not tied to the initiating user session, so CSRF is possible for any attacker that...

1 affected package

python-authlib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-authlib Needs evaluation Needs evaluation
Show less packages

CVE-2025-62706

Medium priority
Needs evaluation

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JWE zip=DEF path performs unbounded DEFLATE decompression. A very small ciphertext can expand into tens or hundreds of...

1 affected package

python-authlib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-authlib Needs evaluation Needs evaluation
Show less packages

CVE-2025-61920

Medium priority
Needs evaluation

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JWS/JWT header and signature segments. A remote attacker can craft a token whose...

1 affected package

python-authlib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-authlib Needs evaluation Needs evaluation
Show less packages

CVE-2025-59420

Medium priority
Needs evaluation

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verification accepts tokens that declare unknown critical header parameters (crit), violating RFC...

1 affected package

python-authlib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-authlib Needs evaluation Needs evaluation
Show less packages

CVE-2024-37568

Medium priority
Vulnerable

lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asymmetric public key. (This is similar...

1 affected package

python-authlib

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-authlib Vulnerable Vulnerable Not in release
Show less packages