CVE-2026-41425 - Authlib: Cross-site request forging when using cache
CVE ID :CVE-2026-41425
Published : April 24, 2026, 8:16 p.m. | 3 hours, 57 minutes ago
Description :Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability is fixed in 1.6.11.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : April 24, 2026, 8:16 p.m. | 3 hours, 57 minutes ago
Description :Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability is fixed in 1.6.11.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...