Debian alert DLA-4708-1 (python-authlib)
| From: | Andrej Shadura <andrewsh@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4708-1] python-authlib security update | |
| Date: | Fri, 31 Jul 2026 17:46:59 +0200 | |
| Message-ID: | <20260731154700.1049254-1-andrewsh@debian.org> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4708-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Andrej Shadura July 31, 2026 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : python-authlib Version : 0.15.4-1+deb11u4 1.2.0-1+deb12u2 CVE ID : CVE-2026-27962 CVE-2026-28490 CVE-2026-28498 CVE-2026-41425 CVE-2026-44681 The following security issue has been identified (and fixed) in python-authlib as shipped in Debian bullseye and Debian bookworm. CVE-2026-44681 An unauthenticated open redirect in Authlib's OpenIDImplicitGrant and OpenIDHybridGrant authorisation endpoint allowed a remote attacker to cause the authorisation server to issue an HTTP 302 to an attacker-chosen URL by submitting an authorisation request that omits the openid scope. For Debian 11 bullseye, this problem has been fixed in version 0.15.4-1+deb11u4. In addition, the following issues have been fixed in the python-authlib version as shipped in Debian bookworm: CVE-2026-27962 Fix authentication and authorization bypass vulnerability by embedding a crafted public key in the jwk header field when key=None is passed to JWS deserialisation functions. CVE-2026-28490 Authlib exposed distinguishable error responses between invalid PKCS#1 v1.5 padding and invalid AES-GCM tag, enabling Bleichenbacher-style attacks. CVE-2026-28498 Fix OIDC ID Token validation bypass in at_hash and c_hash verification. _verify_hash() silently returned True when create_half_hash() received an unknown algorithm, allowing forged ID Tokens to pass validation. CVE-2026-41425 CSRF protection now covers the cache feature in authlib.integrations.starlette_client.OAuth as well. For Debian 12 bookworm, these problems have been fixed in version 1.2.0-1+deb12u2. We recommend that you upgrade your python-authlib packages. For the detailed security status of python-authlib please refer to its security tracker page at: https://security-tracker.debian.org/tracker/python-authlib Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQSD3NF/RLIsyDZW7aHoRGtKyMdyYQUCamzDaQAKCRDoRGtKyMdy YUdjAQDXRiDBcWUtSlsWNJftIaBIefhWyxss9cQrN80H33M79AEAlPNBolsPYEvB s1XncpoAzAOxEZvqD5vlj4Iq804gMgs= =OwKC -----END PGP SIGNATURE-----
