OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-104056

CRITICAL · CVSS 9.8 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

Authlib versions 1.7.2 and earlier are vulnerable due to improper validation of cached discovery JSON metadata, allowing an attacker to inject malicious endpoint values. This could lead to unauthorized access or manipulation of services relying on the compromised metadata. Developers and organizations using Authlib should prioritize remediation to mitigate potential exploitation risks.

CVE
CVE-2026-104056
Severity
CRITICAL
CVSS
9.8
EPSS
0.10%

Original NVD Description

Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values with attacker-controlled values rather than endpoint URLs that share the origin of the configured server metadata URL.