CVE-2026-44681Patch(authlib / authlib)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch authlib authlib systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's OpenIDImplicitGrant and OpenIDHybridGrant authorization endpoint lets a remote attacker cause the authorization server to issue an HTTP 302 to an attacker-chosen URL by submitting an authorization request that omits the openid scope. This vulnerability is fixed in 1.6.12 and 1.7.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-601CWE-863

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • authlib

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
authlib

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-25: 1Patch / Workaround · 2026-06-25: 106-25
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • RazzReport@RazzReport
    Patch

    OpenHands patched 4 CVEs in one window (CVE-2026-44681, 53571, 48712, 54285). Mem0 fixed CVE-2026-12151 (undici). LiteLLM has client key leak redaction in flight. Unusual concentration - possibly coordinated disclosure or shared dependency. @LiteLLM

    Post summary

    OpenHands and Mem0 have issued patches for several CVEs with no evidence of active exploitation or provided technical details.

    1000051
    14 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appauthlibauthlib---
Appauthlibauthlib1.7.0--

Explore more