Medium severity5.4NVD Advisory· Published Apr 24, 2026· Updated Apr 28, 2026
CVE-2026-41425
CVE-2026-41425
Description
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability is fixed in 1.6.11.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/authlib/authlib/security/advisories/GHSA-jj8c-mmj3-mmgvnvdExploitVendor Advisory
- github.com/advisories/GHSA-jj8c-mmj3-mmgvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-41425ghsa
News mentions
0No linked articles in our index yet.