CVE-2026-28498 describes a high-severity vulnerability in the Authlib Python library, affecting versions prior to 1.6.9, where its OpenID Connect (OIDC) ID Token validation fails open. This flaw allows an attacker to bypass integrity checks by providing a forged ID Token with an unrecognized cryptographic algorithm in the 'alg' header, which the library silently accepts. Rated 7.5 HIGH on CVSS, it has a network attack vector with low complexity and no user interaction, leading to high integrity impact. There is currently no evidence of active exploitation, nor are public exploit codes available, and community attention remains low.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.9CPE matchmatch criteria | cpe:2.3:a:authlib:authlib:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.