{"id":"CVE-2025-59420","title":"authlib: Authlib RFC violation (CVE-2025-59420)","summary":"Authlib’s JWS verification accepts tokens that declare unknown critical header parameters (crit), violating RFC 7515 “must‑understand” semantics. An attacker can craft a signed token with a critical header (for example, bork or cnf) that s…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cvssSource":"vendor","cwe":"CWE-440","vendor":"Red Hat","product":"Red Hat Quay 3.10","affected":["quay 3.10","quay 3.12","quay 3.13","quay 3.14","quay 3.15","quay 3.9"],"patched":["quay 3.10","quay 3.12","quay 3.13","quay 3.14","quay 3.15","quay 3.9"],"published":"2025-09-22","updated":"2026-09-21","sourceUpdated":"2026-09-21T16:14:39+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59420.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59420.json"},{"url":"https://access.redhat.com/security/cve/CVE-2025-59420"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2397460"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-59420"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59420"},{"url":"https://github.com/authlib/authlib/commit/6b1813e4392eb7c168c276099ff7783b176479df"},{"url":"https://github.com/authlib/authlib/security/advisories/GHSA-9ggr-2464-2j32"},{"url":"https://access.redhat.com/errata/RHSA-2025:23064"},{"url":"https://access.redhat.com/errata/RHSA-2025:22182"},{"url":"https://access.redhat.com/errata/RHSA-2025:23028"},{"url":"https://access.redhat.com/errata/RHSA-2025:23176"},{"url":"https://access.redhat.com/errata/RHSA-2026:4215"},{"url":"https://access.redhat.com/errata/RHSA-2026:1942"},{"url":"https://access.redhat.com/errata/RHSA-2025:23061"},{"url":"https://access.redhat.com/errata/RHSA-2025:22287"},{"url":"https://github.com/authlib/authlib"},{"url":"https://lists.debian.org/debian-lts-announce/2025/10/msg00032.html"}],"tags":["csaf","vex","red-hat","osv","pip"],"epss":0.00262,"epssPercentile":0.18326,"aliases":["GHSA-9ggr-2464-2j32","PYSEC-2026-1200"],"ecosystem":"pip","ingestedAt":"2026-07-08T18:25:47.857Z","slug":"CVE-2025-59420","body":"## Overview\n\nAuthlib’s JWS verification accepts tokens that declare unknown critical header parameters (crit), violating RFC 7515 “must‑understand” semantics. An attacker can craft a signed token with a critical header (for example, bork or cnf) that strict verifiers reject but Authlib accepts. In mixed‑language fleets, this enables split‑brain verification and can lead to policy bypass, replay, or privilege escalation.\n\n## Vendor advisories\n\n- **RHSA-2025:23064** · Red Hat · fixed in: Red Hat Quay 3.10 · released 2025-12-10 · [advisory](https://access.redhat.com/errata/RHSA-2025:23064)\n- **RHSA-2025:22182** · Red Hat · fixed in: Red Hat Quay 3.10 · released 2025-11-26 · [advisory](https://access.redhat.com/errata/RHSA-2025:22182)\n- **RHSA-2025:23028** · Red Hat · fixed in: Red Hat Quay 3.12 · released 2025-12-10 · [advisory](https://access.redhat.com/errata/RHSA-2025:23028)\n- **RHSA-2025:23176** · Red Hat · fixed in: Red Hat Quay 3.13 · released 2025-12-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:23176)\n- **RHSA-2026:4215** · Red Hat · fixed in: Red Hat Quay 3.14 · released 2026-03-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:4215)\n- **RHSA-2026:1942** · Red Hat · fixed in: Red Hat Quay 3.15 · released 2026-02-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:1942)\n- **RHSA-2025:23061** · Red Hat · fixed in: Red Hat Quay 3.9 · released 2025-12-10 · [advisory](https://access.redhat.com/errata/RHSA-2025:23061)\n- **RHSA-2025:22287** · Red Hat · fixed in: Red Hat Quay 3.9 · released 2025-11-27 · [advisory](https://access.redhat.com/errata/RHSA-2025:22287)\n\n**authlib: Authlib RFC violation** — rated Important by Red Hat. Released 2025-09-22, updated 2026-09-21.\n\nFixed:\n\n- Red Hat Quay 3.10\n- Red Hat Quay 3.12\n- Red Hat Quay 3.13\n- Red Hat Quay 3.14\n- Red Hat Quay 3.15\n- Red Hat Quay 3.9\n\nNot affected:\n\n- Red Hat Quay 3.10\n- Red Hat Quay 3.12\n- Red Hat Quay 3.13\n- Red Hat Quay 3.14\n- Red Hat Quay 3.15\n- Red Hat Quay 3.9\n\n## Remediation\n\nBefore applying this update, make sure all previously released errata relevant\nto your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:23064\nBefore applying this update, make sure all previously released errata relevant\nto your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:22182\nBefore applying this update, make sure all previously released errata relevant\nto your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:23028\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.\n\n## Package advisory (CVE-2025-59420)\n\nAffected packages:\n\n- `authlib < 1.6.4`\n\nPatched in:\n\n- `authlib 1.6.4`\n\nSource: https://osv.dev/vulnerability/GHSA-9ggr-2464-2j32","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}