CVE-2026-28490

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a cryptographic padding oracle vulnerability was identified in the Authlib Python library concerning the implementation of the JSON Web Encryption (JWE) RSA1_5 key management algorithm. Authlib registers RSA1_5 in its default algorithm registry without requiring explicit opt-in, and actively destroys the constant-time Bleichenbacher mitigation that the underlying cryptography library implements correctly. This issue has been patched in version 1.6.9.
Configurations

Configuration 1 (hide)

cpe:2.3:a:authlib:authlib:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:28

Type Values Removed Values Added
Summary
  • (es) Authlib es una biblioteca Python que construye servidores OAuth y OpenID Connect. Antes de la versión 1.6.9, se identificó una vulnerabilidad de oráculo de relleno criptográfico en la biblioteca Python Authlib relacionada con la implementación del algoritmo de gestión de claves RSA1_5 de JSON Web Encryption (JWE). Authlib registra RSA1_5 en su registro de algoritmos predeterminado sin requerir una aceptación explícita, y destruye activamente la mitigación de tiempo constante de Bleichenbacher que la biblioteca de criptografía subyacente implementa correctamente. Este problema ha sido parcheado en la versión 1.6.9.

17 Mar 2026, 20:45

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Authlib authlib
Authlib
References () https://github.com/authlib/authlib/commit/48b345f29f6c459f11c6a40162b6c0b742ef2e22 - () https://github.com/authlib/authlib/commit/48b345f29f6c459f11c6a40162b6c0b742ef2e22 - Patch
References () https://github.com/authlib/authlib/releases/tag/v1.6.9 - () https://github.com/authlib/authlib/releases/tag/v1.6.9 - Product, Release Notes
References () https://github.com/authlib/authlib/security/advisories/GHSA-7432-952r-cw78 - () https://github.com/authlib/authlib/security/advisories/GHSA-7432-952r-cw78 - Exploit, Mitigation, Vendor Advisory
CPE cpe:2.3:a:authlib:authlib:*:*:*:*:*:*:*:*

16 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 18:16

Updated : 2026-06-17 10:28


NVD link : CVE-2026-28490

Mitre link : CVE-2026-28490

CVE.ORG link : CVE-2026-28490


JSON object : View

Products Affected

authlib

  • authlib
CWE
CWE-203

Observable Discrepancy

CWE-327

Use of a Broken or Risky Cryptographic Algorithm