CVE-2026-104056
CVE-2026-104056
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values with attacker-controlled values rather than endpoint URLs that share the origin of the configured server metadata URL.
| Vendor | authlib |
| Product | authlib |
| Published | Oct 1, 2026 |
Stay Ahead of the Next One
Get instant alerts for authlib authlib
Be the first to know when new unknown vulnerabilities affecting authlib authlib are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Authlib / Authlib
1.7.2