CVE-2026-104056: Pypi/authlib vulnerability
Published Oct 1, 2026
·Updated
Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values with attacker-controlled values rather than endpoint URLs that share the origin of the configured server metadata URL.
Affected Software
1 affected component
pypi/authlib<=1.7.2
Event History
Oct 1, 2026
CVE Published
via MITRE·06:03 PM
Data Sourced
via MITRE·06:03 PM
DescriptionWeakness
Data Sourced
via NVD·07:17 PM
Description
Frequently Asked Questions
1
Which deployments should be investigated?
Investigate applications using PyPI Authlib version 1.7.2 or below that cache discovery JSON metadata. The issue concerns cached discovery metadata used to determine endpoint values.
2
What is the impact of a poisoned discovery response?
A poisoned response can replace all discovered endpoint values with attacker-controlled values. Those values are not required to share the origin of the configured server metadata URL.