CVE-2026-41479

MEDIUM CVSS 3.1: 5.4 EPSS 0.26%
Updated Jun 26, 2026
Authlib
Parameter Value
CVSS 5.4 (MEDIUM)
Affected Versions before 1.6.10
Fixed In 1.6.10
Type CWE-601 (Open Redirect)
Vendor Authlib
Public PoC No

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect when a request uses an unsupported response_type and supplies an attacker-controlled redirect_uri. The vulnerable behavior happens before client lookup and before any redirect URI validation.

As a result, an attacker does not need a valid client registration, an authenticated user, or any prior state. A single request to the authorization endpoint is enough to obtain a 302 Location response to an arbitrary attacker-controlled URL. This vulnerability is fixed in 1.6.10 and 1.7.1.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 2

Configuration From (including) Up to (excluding)
Authlib Authlib
cpe:2.3:a:authlib:authlib:*:*:*:*:*:*:*:*
— 1.6.10
Authlib Authlib
cpe:2.3:a:authlib:authlib:1.7.0:*:*:*:*:*:*:*
— —