© 2025-2026 PySpect
First version without a known vulnerability: 1.7.1
Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type
Fixed in: 1.6.10, 1.7.1
Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect
Fixed in: 1.7.1, 1.6.12
Authlib: Cross-site request forging when using cache
Fixed in: 1.6.11
Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding
Fixed in: 1.6.9
Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle
Fixed in: 1.6.9
Authlib JWS JWK Header Injection: Signature Verification Bypass
Fixed in: 1.6.9
Authlib: Setting `alg: none` and a blank signature appears to bypass signature verification
Fixed in: 1.6.7
Authlib has 1-click Account Takeover vulnerability
Fixed in: 1.6.6
Authlib : JWE zip=DEF decompression bomb enables DoS
Fixed in: 1.6.5
Authlib is vulnerable to Denial of Service via Oversized JOSE Segments
Fixed in: 1.6.5
Authlib: JWS/JWT accepts unknown crit headers (RFC violation → possible authz bypass)
Fixed in: 1.6.4
Authlib has algorithm confusion with asymmetric public keys
Fixed in: 1.3.1