Authlib is a focused authentication and authorization library whose modest volume belies its prominence in the supply-chain landscape, embedded in OAuth and OpenID implementations across web applications and API frameworks. Its vulnerabilities skew toward serious outcomes and concentrate in cryptographic-signature verification, resource-consumption control, and authorization logic, reflecting the protocol-state and trust-boundary demands intrinsic to identity middleware. Defenders should monitor this vendor's releases closely and treat authentication-layer patches as high-priority for any service relying on Authlib; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Authlib over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27962CRITICAL Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a JWK Header Injection vulnerability in authlib's JWS implementation allows an un | Mar 16, 2026 | 9.1 | 35 | NO | NO |
CVE-2026-28802CRITICAL Authlib is a Python library which builds OAuth and OpenID Connect servers. From version 1.6.5 to before version 1.6.7, previous tests involving passing a malicious JWT containing a | Mar 6, 2026 | 9.8 | 35 | NO | NO |
CVE-2026-28498HIGH Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concer | Mar 16, 2026 | 7.5 | 28 | NO | NO |
CVE-2025-68158HIGH Authlib is a Python library which builds OAuth and OpenID Connect servers. In versions 1.0.0 through 1.6.5, cache-backed state/request-token storage is not tied to the initiating u | Jan 8, 2026 | 8.8 | 28 | NO | NO |
CVE-2025-61920HIGH Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JWS/JWT header and signature segm | Oct 10, 2025 | 7.5 | 25 | NO | NO |
CVE-2026-44681MEDIUM Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's OpenIDImplicitGrant and OpenIDHy | May 27, 2026 | 6.1 | 24 | NO | NO |
CVE-2025-59420HIGH Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verification accepts tokens that declare unknown critical header pa | Sep 22, 2025 | 7.5 | 24 | NO | NO |
CVE-2026-41479MEDIUM Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticat | Jun 22, 2026 | 5.4 | 23 | NO | NO |
CVE-2026-41425MEDIUM Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_clien | Apr 24, 2026 | 5.4 | 23 | NO | NO |
CVE-2026-28490MEDIUM Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a cryptographic padding oracle vulnerability was identified in the Authlib Python | Mar 16, 2026 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Authlib.
Media articles that mention a CVE ID that affects a product developed by Authlib — matched by CVE ID, not by vendor name.