Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-345 CWE-829 |
|
| Metrics |
cvssV3_1
|
ssvc
|
Fri, 02 Oct 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 |
Fri, 02 Oct 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-346 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Thu, 01 Oct 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 |
Thu, 01 Oct 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Authlib
Authlib authlib |
|
| Vendors & Products |
Authlib
Authlib authlib |
Thu, 01 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values with attacker-controlled values rather than endpoint URLs that share the origin of the configured server metadata URL. | |
| Title | CVE-2026-104056 | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-10-05T18:21:14.480Z
Reserved: 2026-10-01T18:01:19.689Z
Link: CVE-2026-104056
Updated: 2026-10-05T18:21:02.943Z
Status : Awaiting Analysis
Published: 2026-10-01T19:17:19.033
Modified: 2026-10-05T19:17:14.327
Link: CVE-2026-104056
OpenCVE Enrichment
Updated: 2026-10-02T15:30:12Z