Security Flaw in Authlib Impacts Data Integrity for Developers
CVE-2026-104056
Currently unrated
What is CVE-2026-104056?
A security issue has been identified in Authlib versions up to 1.7.2, where JSON metadata is cached without proper validation or binding to the issuer's origin. This flaw allows malicious actors to exploit the vulnerability, enabling them to inject harmful responses that replace legitimate endpoint values with those under their control. Such an attack could significantly undermine the data integrity of applications utilizing Authlib, posing a serious risk to developers and users alike.
Affected Version(s)
Authlib 1.7.2
