{"id":"CVE-2026-41479","aliases":["GHSA-w8p2-r796-3vmq","PYSEC-2026-2119"],"url":"https://o3.security/vulnerability/CVE-2026-41479","summary":"Authlib OAuth 2.0 authorization endpoint open redirects to attacker-controlled redirect_uri on unsupported response_type","details":"Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect when a request uses an unsupported response_type and supplies an attacker-controlled redirect_uri. The vulnerable behavior happens before client lookup and before any redirect URI validation. As a result, an attacker does not need a valid client registration, an authenticated user, or any prior state. A single request to the authorization endpoint is enough to obtain a 302 Location response to an arbitrary attacker-controlled URL. This vulnerability is fixed in 1.6.10 and 1.7.1.","published":"2026-06-22T20:35:13.699Z","modified":"2026-08-12T03:51:37.151548483Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"},"epss":{"score":0.00257,"percentile":0.17021,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"authlib","fixedVersion":"1.6.10"},{"ecosystem":"PyPI","name":"authlib","fixedVersion":"1.7.1"}],"fix":{"url":"https://github.com/authlib/authlib/commit/3be08468201a7766a93012ce149ea12822cab096","label":"authlib/authlib@3be0846"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41479.json"},{"type":"ADVISORY","url":"https://github.com/authlib/authlib/security/advisories/GHSA-w8p2-r796-3vmq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41479"},{"type":"FIX","url":"https://github.com/authlib/authlib/commit/3be08468201a7766a93012ce149ea12822cab096"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:37.151548483Z"}}