CSRF Vulnerability in Authlib Python Library Affecting OAuth and OpenID Integration
CVE-2026-41425

5.4MEDIUM

Key Information:

Vendor

Authlib

Status
Vendor
CVE Published:
24 April 2026

What is CVE-2026-41425?

The Authlib Python library, which facilitates the creation of OAuth and OpenID Connect servers, is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability. This issue is particularly concerning as it affects the cache feature within the authlib.integrations.starlette_client.OAuth before version 1.6.11. Without adequate CSRF protection, attackers could exploit this flaw to carry out unauthorized actions. Users of Authlib are strongly advised to upgrade to version 1.6.11 or later to mitigate this vulnerability and ensure robust security for their applications.

Affected Version(s)

authlib < 1.6.11

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.