Description
Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values with attacker-controlled values rather than endpoint URLs that share the origin of the configured server metadata URL.
Published: 2026-10-01
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthorized endpoint replacement
Action: Apply Patch
AI Analysis

Impact

Authlib libraries up to version 1.7.2 store OpenID Connect discovery documents in cache without validating the issuer claim or ensuring that the values are hosted on the same origin as the discovery endpoint. This lack of validation means that an attacker can return a malicious discovery JSON that replaces every endpoint field (authorization_endpoint, token_endpoint, etc.) with attacker‑controlled URLs, and the library will cache these substitutes.

Affected Systems

The affected product is the Authlib library from the Authlib project, versions 1.7.2 and earlier. No other vendors or products are listed as affected.

Risk and Exploitability

The vulnerability is exploitable as long as an application can receive a poisoned discovery document during its normal OIDC discovery process. Because the response is cached, the attack can persist until the cache is cleared or the library is updated. No CVSS or EPSS score is publicly available, and the vulnerability is not listed in CISA KEV. The risk therefore relies on the absence of validation rather than a known exploitation rate. Attackers can manipulate the authentication flow by redirecting endpoint URLs to malicious servers.

Generated by OpenCVE AI on October 1, 2026 at 19:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Authlib to the latest version that validates discovery responses.
  • Configure Authlib to enforce issuer‑origin binding so that only endpoints from the discovery document’s origin are accepted, if the library supports this setting.
  • Apply network controls to restrict the application’s ability to fetch discovery documents from untrusted or arbitrary endpoints.

Generated by OpenCVE AI on October 1, 2026 at 19:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20

Thu, 01 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Authlib
Authlib authlib
Vendors & Products Authlib
Authlib authlib

Thu, 01 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Description Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values with attacker-controlled values rather than endpoint URLs that share the origin of the configured server metadata URL.
Title CVE-2026-104056
References

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-10-01T18:03:27.484Z

Reserved: 2026-10-01T18:01:19.689Z

Link: CVE-2026-104056

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-01T19:17:19.033

Modified: 2026-10-01T20:37:42.787

Link: CVE-2026-104056

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T20:00:12Z

Weaknesses
  • CWE-20

    Improper Input Validation