CVE Explorer
CVE-2026-41425
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.11, there is no CSRF protection on the cache feature in authlib.integrations.starlette_client.OAuth. This vulnerability is fixed in 1.6.11.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"authlib","vendor":"authlib","versions":[{"status":"affected","version":"< 1.6.11"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:5a70f7b28951b6625c511dae606abc4d0f48216bc64986225891825250c3198f · sha256:35376f8a396d41ce… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.4,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:5a70f7b28951b6625c511dae606abc4d0f48216bc64986225891825250c3198f · sha256:35376f8a396d41ce… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-352","description":"CWE-352: Cross-Site Request Forgery (CSRF)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:5a70f7b28951b6625c511dae606abc4d0f48216bc64986225891825250c3198f · sha256:35376f8a396d41ce… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["exploit"],"url":"https://github.com/authlib/authlib/security/advisories/GHSA-jj8c-mmj3-mmgv"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5a70f7b28951b6625c511dae606abc4d0f48216bc64986225891825250c3198f · sha256:35376f8a396d41ce… · /containers/adp/0/references/0
{"name":"https://github.com/authlib/authlib/security/advisories/GHSA-jj8c-mmj3-mmgv","tags":["x_refsource_CONFIRM"],"url":"https://github.com/authlib/authlib/security/advisories/GHSA-jj8c-mmj3-mmgv"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:5a70f7b28951b6625c511dae606abc4d0f48216bc64986225891825250c3198f · sha256:35376f8a396d41ce… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.