Technology · PyPI
authlib (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 12 vulnerabilities in authlib (PyPI): 0 in the last 7 days and 4 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2025-68158, was published on 7 July 2026.
- Last 7 days
- 0
- Last 90 days
- 4
- Critical, all time
- 2
- Exploited in the wild
- 0
About authlib (PyPI)
A Python library for building OAuth and OpenID Connect servers and clients.
Latest authlib (PyPI) vulnerabilities
- CVE-2025-68158: PYSEC-2026-1201 - Authlib has 1-click Account Takeover vulnerabilitylowCVSS 3.1EPSS 0.3%
- CVE-2025-62706: PYSEC-2026-1202 - Authlib : JWE zip=DEF decompression bomb enables DoSlowCVSS 3.1EPSS 0.5%
- CVE-2025-61920: PYSEC-2026-1203 - Authlib is vulnerable to Denial of Service via Oversized JOSE SegmentslowCVSS 3.1EPSS 0.6%
- CVE-2025-59420: PYSEC-2026-1200 - Authlib: JWS/JWT accepts unknown crit headers (RFC violation → possible authz bypass)lowCVSS 3.1EPSS 0.3%
- CVE-2026-41479: Authlib open redirect in OAuth 2.0 authorization endpointmediumCVSS 5.4EPSS 0.3%
- CVE-2026-44681: Authlib open redirect in OIDC Implicit and Hybrid grantsmediumCVSS 6.1EPSS 0.3%
- CVE-2026-41425: Authlib CSRF in OAuth integrations when using cache storagemediumCVSS 5.4EPSS 0.1%
- CVE-2026-28498: Authlib fail-open cryptographic verification in OIDC hash bindinghighCVSS 7.5EPSS 0.3%
- CVE-2026-28490: PYSEC-2026-2116 - Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a…mediumCVSS 4EPSS 0.2%
- CVE-2026-27962: Authlib JWK Header Injection signature verification bypasscriticalCVSS 9.1EPSS 0.5%
- CVE-2026-28802: Authlib signature verification bypass via none algorithm in JWTcriticalCVSS 9.8EPSS 0.5%
- CVE-2024-37568: PYSEC-2024-52 - lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is…lowCVSS 3.1EPSS 0.4%
Most severe authlib (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-28802: Authlib signature verification bypass via none algorithm in JWTcriticalCVSS 9.8EPSS 0.5%
- CVE-2026-27962: Authlib JWK Header Injection signature verification bypasscriticalCVSS 9.1EPSS 0.5%
- CVE-2026-28498: Authlib fail-open cryptographic verification in OIDC hash bindinghighCVSS 7.5EPSS 0.3%
- CVE-2026-44681: Authlib open redirect in OIDC Implicit and Hybrid grantsmediumCVSS 6.1EPSS 0.3%
- CVE-2026-41479: Authlib open redirect in OAuth 2.0 authorization endpointmediumCVSS 5.4EPSS 0.3%
- CVE-2026-41425: Authlib CSRF in OAuth integrations when using cache storagemediumCVSS 5.4EPSS 0.1%
- CVE-2026-28490: PYSEC-2026-2116 - Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a…mediumCVSS 4EPSS 0.2%
- CVE-2025-61920: PYSEC-2026-1203 - Authlib is vulnerable to Denial of Service via Oversized JOSE SegmentslowCVSS 3.1EPSS 0.6%
- CVE-2025-62706: PYSEC-2026-1202 - Authlib : JWE zip=DEF decompression bomb enables DoSlowCVSS 3.1EPSS 0.5%
- CVE-2024-37568: PYSEC-2024-52 - lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is…lowCVSS 3.1EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 4 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/authlib.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "authlib (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/authlib, 27 September 2026.