---
id: CVE-2025-59420
title: 'authlib: Authlib RFC violation (CVE-2025-59420)'
summary: >-
  Authlib’s JWS verification accepts tokens that declare unknown critical header
  parameters (crit), violating RFC 7515 “must‑understand” semantics. An attacker
  can craft a signed token with a critical header (for example, bork or cnf)
  that s…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cvssSource: vendor
cwe: CWE-440
vendor: Red Hat
product: Red Hat Quay 3.10
affected:
  - quay 3.10
  - quay 3.12
  - quay 3.13
  - quay 3.14
  - quay 3.15
  - quay 3.9
patched:
  - quay 3.10
  - quay 3.12
  - quay 3.13
  - quay 3.14
  - quay 3.15
  - quay 3.9
published: '2025-09-22'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T16:14:39+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59420.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59420.json
  - url: 'https://access.redhat.com/security/cve/CVE-2025-59420'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2397460'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-59420'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-59420'
  - url: >-
      https://github.com/authlib/authlib/commit/6b1813e4392eb7c168c276099ff7783b176479df
  - url: 'https://github.com/authlib/authlib/security/advisories/GHSA-9ggr-2464-2j32'
  - url: 'https://access.redhat.com/errata/RHSA-2025:23064'
  - url: 'https://access.redhat.com/errata/RHSA-2025:22182'
  - url: 'https://access.redhat.com/errata/RHSA-2025:23028'
  - url: 'https://access.redhat.com/errata/RHSA-2025:23176'
  - url: 'https://access.redhat.com/errata/RHSA-2026:4215'
  - url: 'https://access.redhat.com/errata/RHSA-2026:1942'
  - url: 'https://access.redhat.com/errata/RHSA-2025:23061'
  - url: 'https://access.redhat.com/errata/RHSA-2025:22287'
  - url: 'https://github.com/authlib/authlib'
  - url: 'https://lists.debian.org/debian-lts-announce/2025/10/msg00032.html'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - pip
epss: 0.00262
epssPercentile: 0.16076
aliases:
  - GHSA-9ggr-2464-2j32
  - PYSEC-2026-1200
ecosystem: pip
ingestedAt: '2026-07-08T18:25:47.857Z'
---

## Overview

Authlib’s JWS verification accepts tokens that declare unknown critical header parameters (crit), violating RFC 7515 “must‑understand” semantics. An attacker can craft a signed token with a critical header (for example, bork or cnf) that strict verifiers reject but Authlib accepts. In mixed‑language fleets, this enables split‑brain verification and can lead to policy bypass, replay, or privilege escalation.

## Vendor advisories

- **RHSA-2025:23064** · Red Hat · fixed in: Red Hat Quay 3.10 · released 2025-12-10 · [advisory](https://access.redhat.com/errata/RHSA-2025:23064)
- **RHSA-2025:22182** · Red Hat · fixed in: Red Hat Quay 3.10 · released 2025-11-26 · [advisory](https://access.redhat.com/errata/RHSA-2025:22182)
- **RHSA-2025:23028** · Red Hat · fixed in: Red Hat Quay 3.12 · released 2025-12-10 · [advisory](https://access.redhat.com/errata/RHSA-2025:23028)
- **RHSA-2025:23176** · Red Hat · fixed in: Red Hat Quay 3.13 · released 2025-12-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:23176)
- **RHSA-2026:4215** · Red Hat · fixed in: Red Hat Quay 3.14 · released 2026-03-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:4215)
- **RHSA-2026:1942** · Red Hat · fixed in: Red Hat Quay 3.15 · released 2026-02-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:1942)
- **RHSA-2025:23061** · Red Hat · fixed in: Red Hat Quay 3.9 · released 2025-12-10 · [advisory](https://access.redhat.com/errata/RHSA-2025:23061)
- **RHSA-2025:22287** · Red Hat · fixed in: Red Hat Quay 3.9 · released 2025-11-27 · [advisory](https://access.redhat.com/errata/RHSA-2025:22287)

**authlib: Authlib RFC violation** — rated Important by Red Hat. Released 2025-09-22, updated 2026-09-21.

Fixed:

- Red Hat Quay 3.10
- Red Hat Quay 3.12
- Red Hat Quay 3.13
- Red Hat Quay 3.14
- Red Hat Quay 3.15
- Red Hat Quay 3.9

Not affected:

- Red Hat Quay 3.10
- Red Hat Quay 3.12
- Red Hat Quay 3.13
- Red Hat Quay 3.14
- Red Hat Quay 3.15
- Red Hat Quay 3.9

## Remediation

Before applying this update, make sure all previously released errata relevant
to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:23064
Before applying this update, make sure all previously released errata relevant
to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:22182
Before applying this update, make sure all previously released errata relevant
to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:23028

Workarounds / mitigations:

- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

## Package advisory (CVE-2025-59420)

Affected packages:

- `authlib < 1.6.4`

Patched in:

- `authlib 1.6.4`

Source: https://osv.dev/vulnerability/GHSA-9ggr-2464-2j32
