๐Ÿ” CVE Alert

CVE-2026-104056

UNKNOWN 0.0

CVE-2026-104056

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values with attacker-controlled values rather than endpoint URLs that share the origin of the configured server metadata URL.

Vendor authlib
Product authlib
Published Oct 1, 2026
Stay Ahead of the Next One

Get instant alerts for authlib authlib

Be the first to know when new unknown vulnerabilities affecting authlib authlib are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Authlib / Authlib
1.7.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
uziii2208.github.io: https://uziii2208.github.io/post/cve-2026-104056/