CVE-2026-41479
Reported by GitHub_M · Published June 22, 2026
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect when a request uses an unsupported response_type and supplies an attacker-controlled redirect_uri. The vulnerable behavior happens before client lookup and before any redirect URI validation. As a result, an attacker does not need a valid client registration, an authenticated user, or any prior state. A single request to the authorization endpoint is enough to obtain a 302 Location response to an arbitrary attacker-controlled URL. This vulnerability is fixed in 1.6.10 and 1.7.1.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| authlib | authlib | < 1.6.10, = 1.7.0 |
| chainguard | mlflow | 0 |
| wolfi | mlflow | 0, 0 |
| PyPI | authlib | 0, 1.7.0, 0 |
| authlib | authlib | < 1.6.10, = 1.7.0, < 1.6.10 |
Timeline
- Jun 8, 2026 CVE Published
- Jun 11, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Sep 5, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 10, 2026 EPSS Score
- Sep 15, 2026 EPSS Score
References
- https://github.com/authlib/authlib/security/advisories/GHSA-w8p2-r796-3vmq x_refsource_CONFIRM
- https://github.com/authlib/authlib/commit/3be08468201a7766a93012ce149ea12822cab096 x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2026-41479 advisory
- https://github.com/advisories/GHSA-w8p2-r796-3vmq advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/authlib/PYSEC-2026-2119.yaml advisory