Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-68158

28
FAUCET Score

CVE-2025-68158 describes a Cross-Site Request Forgery (CSRF) vulnerability in Authlib, a Python library for OAuth and OpenID Connect servers, affecting versions 1.6.5 and prior. The flaw stems from cache-backed state/request-token storage not being tied to the initiating user session, allowing an attacker to obtain a valid state and exploit the vulnerability. This issue carries a high CVSS score of 8.8, indicating a critical risk with potential for high impact on confidentiality, integrity, and availability, requiring user interaction but no authentication. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, including security updates from SUSE and Ubuntu.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.6.6CPE matchmatch criteria
cpe:2.3:a:authlib:authlib:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.7MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.1
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
14.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 15th percentile among its peer group of 14,875 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: authlibFixed in: 1.6.6
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: ansible-automation-platform-25/lightspeed-chatbot-rhel8
redhatno patchvia redhat_api
Product: Red Hat Quay 3Fixed in: quay/quay-rhel9
redhatno patchvia redhat_api
Product: Red Hat Satellite 6Fixed in: satellite/foreman-mcp-server-rhel9

Vendor Advisories (2)

pipGHSA-fg6f-75jq-6523medium

Authlib has 1-click Account Takeover vulnerability

Jan 8, 2026
redhatCVE-2025-68158Moderate

Authlib: Authlib: Cross-Site Request Forgery due to improper session management in state storage

Jan 8, 2026

References

github.com / authlib/authlib/commit/2808378611dd6fb2532b189a9087877d8f0c0489
Patch
github.com / authlib/authlib/commit/7974f45e4d7492ab5f527577677f2770ce423228
Patch
github.com / authlib/authlib/security/advisories/GHSA-fg6f-75jq-6523
ExploitVendor Advisory