Junglewise Threat Intelligence

CVE-2026-28498: Authlib fail-open cryptographic verification in OIDC hash binding

CVE-2026-28498 · Severity: high · CVSS 7.5 · Published 2026-03-16

Technologies: authlib (PyPI). Vendors: Red Hat, PyPI, Authlib.

Executive brief

Authlib is a popular Python library used by developers to build secure login systems using standards like OAuth and OpenID Connect. A flaw in the library's security checks allows an attacker to bypass mandatory integrity protections by using a specially crafted login token. This could allow an attacker to substitute legitimate security codes or access tokens with malicious ones, potentially leading to unauthorized access or account takeover in applications that rely on this library.

Technical details

A vulnerability exists in Authlib's internal hash verification logic (_verify_hash) within authlib/oidc/core/claims.py. When validating the at_hash (Access Token Hash) or c_hash (Authorization Code Hash) claims, the library calls create_half_hash. If an attacker provides a forged ID Token with an unsupported or unknown 'alg' header parameter, create_half_hash returns None. The _verify_hash function incorrectly interprets this None value as a successful validation and returns True instead of failing. This fail-open state allows an attacker to perform token substitution attacks in Hybrid or Implicit OIDC flows, bypassing the cryptographic binding between the ID Token and the Access Token or Authorization Code. The issue is fixed in version 1.6.9 by ensuring the function returns False when the hash cannot be computed.

Affected products

  • authlib Authlib <= 1.6.8
  • Red Hat Red Hat Ansible Automation Platform 2.6
  • Red Hat Red Hat Quay 3.12
  • Red Hat Red Hat Quay 3.15
  • Red Hat Red Hat Quay 3.16
  • Red Hat Red Hat Satellite 6

Timeline

  • 2026-03-02: patched: Version 1.6.9 released
  • 2026-03-15: advisory: GitHub Security Advisory published
  • 2026-03-16: disclosed: CVE published to NVD

References

Related threats