THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-28498 (HIGH 7.5) — Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification

[NVD] CVE-2026-28498 (HIGH 7.5) — Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification

lownvdPublished 2026-03-16

CVE-2026-28498 CVSS: 7.5 HIGH Published: 2026-03-16T18:16:07.717

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (_verify_hash) responsible for validating the a

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-28498