PT-2026-103966 · Oauthlib · Oauthlib

CVE-2026-104056

·

Published

2026-10-01

·

Updated

2026-10-01

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values with attacker-controlled values rather than endpoint URLs that share the origin of the configured server metadata URL.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-104056

Affected Products

Oauthlib