CVE-2026-28490
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a cryptographic padding oracle vulnerability was identified in the Authlib Python library concerning the implementation of the JSON Web Encryption (JWE) RSA1_5 key management algorithm. Authlib registers RSA1_5 in its default algorithm registry without requiring explicit opt-in, and actively destroys the constant-time Bleichenbacher mitigation that the underlying cryptography library implements correctly. This issue has been patched in version 1.6.9.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.3
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.14%
- CWE
- CWE-203, CWE-327
- Published
- 2026-03-16
- Last modified
- 2026-03-16
Affected products
- authlib authlib
Weakness type
Related vulnerabilities
- CVE-2026-87459 — Observable discrepancy in Select in Google Chrome prior to 153.0.8010.36 allowed a remote attacker...
- CVE-2026-87620 — Observable discrepancy in SVG in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to...
- CVE-2026-87619 — Observable discrepancy in Prefetch in Google Chrome prior to 153.0.8010.36 allowed a remote...
- CVE-2026-87566 — Observable discrepancy in Layout in Google Chrome prior to 153.0.8010.36 allowed a remote attacker...
- CVE-2026-87623 — Observable discrepancy in DOM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker...
- CVE-2026-87518 — Observable discrepancy in Safebrowsing in Google Chrome on on iOS prior to 153.0.8010.36 allowed a...
- CVE-2026-87516 — Observable discrepancy in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote...
- CVE-2026-87539 — Observable discrepancy in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker...