Unrated severityNVD Advisory· Published Oct 1, 2026· Updated Oct 1, 2026
CVE-2026-104056
CVE-2026-104056
Description
Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values with attacker-controlled values rather than endpoint URLs that share the origin of the configured server metadata URL.
Affected products
1Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.