CVE-2025-59420 is a high-severity vulnerability affecting Authlib, a Python library for OAuth and OpenID Connect servers, specifically versions prior to 1.6.4. It allows an attacker to craft signed tokens with critical header parameters that Authlib accepts but strict verifiers reject, leading to "split-brain" verification in mixed-language environments. This can result in policy bypass, replay attacks, or privilege escalation. The vulnerability has a CVSS score of 7.5 (High) and is easily exploitable over the network with no user interaction, impacting integrity. While there is no known active exploitation or public exploit code, the issue has garnered some community discussion and media coverage, indicating awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.4CPE matchmatch criteria | cpe:2.3:a:authlib:authlib:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.