Impact
Authlib libraries up to version 1.7.2 store OpenID Connect discovery documents in cache without validating the issuer claim or ensuring that the values are hosted on the same origin as the discovery endpoint. This lack of validation means that an attacker can return a malicious discovery JSON that replaces every endpoint field (authorization_endpoint, token_endpoint, etc.) with attacker‑controlled URLs, and the library will cache these substitutes.
Affected Systems
The affected product is the Authlib library from the Authlib project, versions 1.7.2 and earlier. No other vendors or products are listed as affected.
Risk and Exploitability
The vulnerability is exploitable as long as an application can receive a poisoned discovery document during its normal OIDC discovery process. Because the response is cached, the attack can persist until the cache is cleared or the library is updated. No CVSS or EPSS score is publicly available, and the vulnerability is not listed in CISA KEV. The risk therefore relies on the absence of validation rather than a known exploitation rate. Attackers can manipulate the authentication flow by redirecting endpoint URLs to malicious servers.
OpenCVE Enrichment