CVE-2026-28498

EUVD-2026-12482
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (_verify_hash) responsible for validating the at_hash (Access Token Hash) and c_hash (Authorization Code Hash) claims exhibits a fail-open behavior when encountering an unsupported or unknown cryptographic algorithm. This flaw allows an attacker to bypass mandatory integrity protections by supplying a forged ID Token with a deliberately unrecognized alg header parameter. The library intercepts the unsupported state and silently returns True (validation passed), inherently violating fundamental cryptographic design principles and direct OIDC specifications. This issue has been patched in version 1.6.9.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
Affected Products (NVD)
VendorProductVersion
authlibauthlib
𝑥
< 1.6.9
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
Red HatRed Hat Ansible Automation Platform 2.6
1774417022 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.1
1775169155 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.12
1775253092 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.15
1775169219 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.16
1775069491 ≤
𝑥
< *
ADP
Red HatRed Hat Quay 3.16
1775169226 ≤
𝑥
< *
ADP
Debian logo
Debian Releases
Debian Product
Codename
python-authlib
bookworm
vulnerable
bullseye
vulnerable
bullseye (security)
0.15.4-1+deb11u2
fixed
forky
1.7.2-2
fixed
sid
1.7.2-2
fixed
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-authlib
jammy
Fixed 0.15.5-1ubuntu0.1~esm2
released
noble
Fixed 1.3.0-1ubuntu0.1~esm2
released
questing
ignored
resolute
Fixed 1.6.7-1ubuntu0.1~esm1
released