📦 Authlib

by Authlib

🔍 What is Authlib?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-61920

HIGH CVSS 7.5 Oct 10, 2025

This vulnerability in Authlib allows remote attackers to craft malicious JWT tokens with extremely large header or signature segments, causing excessive CPU and memory consumption during parsing. This...

CVE-2025-59420

HIGH CVSS 7.5 Sep 22, 2025

Authlib versions before 1.6.4 fail to properly validate JWS tokens with unknown critical header parameters, violating RFC 7515 requirements. Attackers can craft tokens that bypass strict verification ...

CVE-2024-37568

HIGH CVSS 7.5 Jun 9, 2024

This vulnerability allows attackers to forge JWT tokens by exploiting algorithm confusion in lepture Authlib. When jwt.decode() is called without specifying an algorithm, the library incorrectly accep...

CVE-2025-68158

MEDIUM CVSS 5.7 Jan 8, 2026

This CSRF vulnerability in Authlib allows attackers to bypass Cross-Site Request Forgery protections in OAuth flows. Attackers can hijack authentication sessions by obtaining valid state tokens throug...

CVE-2025-62706

MEDIUM CVSS 6.5 Oct 22, 2025

CVE-2025-62706 is a denial-of-service vulnerability in Authlib's JWE implementation where DEFLATE decompression lacks size limits. Attackers can send specially crafted tokens that cause excessive memo...