LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-28498

authlib · authlib

Published
CVSS7.5
Severityhigh
WeaknessCWE-354
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Description

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (_verify_hash) responsible for validating the at_hash (Access Token Hash) and c_hash (Authorization Code Hash) claims exhibits a fail-open behavior when encountering an unsupported or unknown cryptographic algorithm. This flaw allows an attacker to bypass mandatory integrity protections by supplying a forged ID Token with a deliberately unrecognized alg header parameter. The library intercepts the unsupported

References

← Back to the CVE Tracker

Our coverage of CVE-2026-28498

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-28498.