CVE-2026-28498Disclosure(authlib / authlib)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch authlib authlib systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (_verify_hash) responsible for validating the at_hash (Access Token Hash) and c_hash (Authorization Code Hash) claims exhibits a fail-open behavior when encountering an unsupported or unknown cryptographic algorithm. This flaw allows an attacker to bypass mandatory integrity protections by supplying a forged ID Token with a deliberately unrecognized alg header parameter. The library intercepts the unsupported state and silently returns True (validation passed), inherently violating fundamental cryptographic design principles and direct OIDC specifications. This issue has been patched in version 1.6.9.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-354CWE-573CWE-325

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • authlib

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-16); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
authlib

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-16: 2Mentions · 2026-03-17: 1Patch / Workaround · 2026-03-17: 1Technical Details · 2026-03-16: 203-1603-17
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-162
Disclosure1General1
2026-03-171
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-28498 Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python … https://www.cve.org/CVERecord?id=CVE-2026-28498

    Post summary

    The text announces a vulnerability in Authlib (CVE‑2026‑28498) that existed before v1.6.9, implying that version 1.6.9 includes a fix.

    00010124
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-28498 - Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding Intel Report: https://ift.tt/Rq5FsW1

    Post summary

    A threat alert has been issued for CVE-2026-28498, describing a fail‑open OIDC hash binding verification flaw in Authlib, with an intel report link provided.

    0000057
    335 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-28498 - Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding Intel Report: https://ift.tt/1rJMkOt

    Post summary

    The alert announces the CVE-2026-28498 vulnerability, describes it as a fail-open cryptographic verification issue in Authlib’s OIDC hash binding, and links to an Intel Report, but it provides no evidence of exploitation, tooling, or remediation.

    0000051
    335 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appauthlibauthlib---

Explore more