CVE-2026-104056

Publication date 5 October 2026

Last updated 5 October 2026


Ubuntu priority

Description

Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values with attacker-controlled values rather than endpoint URLs that share the origin of the configured server metadata URL.

Status

Package Ubuntu Release Status
python-authlib 26.04 LTS resolute
Needs evaluation
24.04 LTS noble
Needs evaluation
22.04 LTS jammy
Needs evaluation


Access our resources on patching vulnerabilities