Junglewise Threat Intelligence

CVE-2026-44681: Authlib open redirect in OIDC Implicit and Hybrid grants

CVE-2026-44681 · Severity: medium · CVSS 6.1 · Published 2026-05-27

Technologies: authlib (PyPI). Vendors: Authlib, PyPI.

Executive brief

Authlib, a library used to implement login and authorization services, contains a flaw that allows attackers to redirect users to malicious websites. By sending a specially crafted login request that omits a required security setting, an attacker can trick the server into sending a user to a phishing page. This can be used to steal user credentials by making the malicious site appear as if it is part of a trusted login process.

Technical details

An open redirect exists in Authlib's `OpenIDImplicitGrant` and `OpenIDHybridGrant` implementations. The vulnerability occurs because the `validate_authorization_request` method checks for the presence of the 'openid' scope before validating the `redirect_uri` against the registered client configuration. If the scope is missing, the library raises an `InvalidScopeError` that includes the unvalidated `redirect_uri` from the request payload. When this error is processed, the server issues an HTTP 302 redirect to the attacker-supplied URL. This bypasses standard OAuth 2.0 security requirements that mandate URI validation before redirection. The issue is fixed in versions 1.6.12 and 1.7.1.

Affected products

  • Authlib Authlib <= 1.6.11, 1.7.0

Timeline

  • 2026-05-07: advisory: GitHub Advisory published
  • 2026-05-13: disclosed

References

Related threats