CVE-2026-104056None▾ SunlitAuthlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values with attacker-controll…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values with attacker-controlled values rather than endpoint URLs that share the origin of the configured server metadata URL.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-96760Critical· 9.8Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability
CVE-2026-28498High· 7.5Authlib is a Python library which builds OAuth and OpenID Connect servers
CVE-2026-27962Critical· 9.1Authlib is a Python library which builds OAuth and OpenID Connect servers
CVE-2026-28802Critical· 9.8Authlib is a Python library which builds OAuth and OpenID Connect servers
CVE-2026-102677High· 7.8Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
CVE-2026-101278Medium· 4.3A weakness has been identified in Trusted Domain Project OpenDMARC up to 1.4.2