CVE-2026-44681

EUVD-2026-32637
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's OpenIDImplicitGrant and OpenIDHybridGrant authorization endpoint lets a remote attacker cause the authorization server to issue an HTTP 302 to an attacker-chosen URL by submitting an authorization request that omits the openid scope. This vulnerability is fixed in 1.6.12 and 1.7.1.
Open Redirect
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 15.97%
Affected Products (NVD)
VendorProductVersion
authlibauthlib
𝑥
< 1.6.12
authlibauthlib
1.7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
python-authlib
bookworm
vulnerable
bookworm (security)
1.2.0-1+deb12u2
fixed
bullseye
vulnerable
bullseye (security)
0.15.4-1+deb11u4
fixed
forky
1.7.2-2
fixed
sid
1.7.2-2
fixed
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
python-authlib
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage