Ubuntu alert USN-8557-1 (python-authlib)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8557-1] Authlib vulnerabilities | |
| Date: | Thu, 16 Jul 2026 19:32:46 +0000 | |
| Message-ID: | <E1wkRp8-00047p-T5@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8557-1 July 16, 2026 python-authlib vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Authlib. Software Description: - python-authlib: Python library for building OAuth and OpenID Connect servers Details: Jay Neiva and Mauro Carrillo discovered that Authlib did not properly validate cryptographic keys embedded in JWT headers. An attacker could possibly use this issue to forge trusted tokens, resulting in authentication and authorization bypass. (CVE-2026-27962) Jay Neiva and Mauro Carrillo discovered that Authlib incorrectly handled RSA1_5 encrypted tokens. An attacker could possibly use this issue to recover sensitive encrypted information, resulting in information disclosure. (CVE-2026-28490) Jay Neiva and Mauro Carrillo discovered that Authlib did not properly reject unsupported cryptographic algorithms when validating OpenID Connect ID tokens. An attacker could possibly use this issue to bypass token integrity checks, resulting in authentication bypass. (CVE-2026-28498) Johnny Deuss discovered that Authlib did not provide cross-site request forgery protection for the OAuth cache feature in its Starlette integration. An attacker could possibly use this issue to perform unauthorized OAuth actions, resulting in cross-site request forgery. This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS. (CVE-2026-41425) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS python3-authlib 1.6.7-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 24.04 LTS python3-authlib 1.3.0-1ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 22.04 LTS python3-authlib 0.15.5-1ubuntu0.1~esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8557-1 CVE-2026-27962, CVE-2026-28490, CVE-2026-28498, CVE-2026-41425
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmpZMAYACgkQcpJm3tlz hgE8BQ/+IgqsePnKCG/VwqJfIrHTis4v+j97wjCQAFvdE0cE0D1toif8NYt3ySFc HQ7Jgq3hRgH7ooKOVlBMQp/kgVeJxrowp1DMUFKKDIh1PnjWMLHfxlWCkAMca6mE +u5wms6zdC+ufI5jNqvYh5zfWuJi7vK9p5zya+SDDhrFr2oSzBB5T2GNYSlVhssH UkUqVjDQfOT4Pq05iPk8bU03bE49CZm1393zREN9+37ee6R8zaHXfUbpZV/ZygR8 PszZnKhyS7zGIXadoi8nEFJiEjkR+6h73nY4/y2tBt3Fu0/9koEK/pXIZAvKsN0z fedXy6GbkAUu20o1FiWf/8SyJ7JG2LNA2+AfvJclofGaPRQXErvgd3KBCaTzZ2aw xmjRRXOMS2aara0DZ74JbW/OqP3PehkfgVqrAkB2ZHmUdzz90cAReFh35J+bfIPN 1F0M2oVSxB+W3CHESw3dKUV4S3Q2HH/EoLrWgAreYumq32Ai3yt7zcFEggMnis5h QU4bKvkZ/Iu/wCZ7qGqkh7BZSu7UDp2bIN/ZrsXrLl3B1emGXxyyC+SMbk7qIrbf yJEtDmS/FhAoCqu2L/ANsXx/EnQpNRZdno4uUCyPXbfoLOZee5vTQXg0goLzbGtP Wjmcl+huQUBIkTiGNNIuHqp0DzKu4ImoXRzkAgQIO7RwDCpo90g= =I4LL -----END PGP SIGNATURE-----
