Security Flaw in Authlib Impacts Data Integrity for Developers
CVE-2026-104056

Currently unrated

Key Information:

Vendor

Authlib

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-104056?

A security issue has been identified in Authlib versions up to 1.7.2, where JSON metadata is cached without proper validation or binding to the issuer's origin. This flaw allows malicious actors to exploit the vulnerability, enabling them to inject harmful responses that replace legitimate endpoint values with those under their control. Such an attack could significantly undermine the data integrity of applications utilizing Authlib, posing a serious risk to developers and users alike.

Affected Version(s)

Authlib 1.7.2

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.