CVE-2025-59420

unknown
Published 2025-09-22 · Modified 2026-02-04
CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v2
VIR risk

Description

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.4, Authlib’s JWS verification accepts tokens that declare unknown critical header parameters (crit), violating RFC 7515 “must‑understand” semantics. An attacker can craft a signed token with a critical header (for example, bork or cnf) that strict verifiers reject but Authlib accepts. In mixed‑language fleets, this enables split‑brain verification and can lead to policy bypass, replay, or privilege escalation. This issue has been patched in version 1.6.4.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2025-59420

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1.2.0-1+deb12u1
debian debianbullseyefixed0.15.4-1+deb11u1
debian debianforkyfixed1.6.4-1
debian debiansidfixed1.6.4-1
debian debiantrixiefixed1.6.0-1+deb13u1

Package impact

EcosystemPackageVulnerableFixed
python PyPIauthlib<1.6.41.6.4

References

Verify integrity in audit chain (admin only). AS-IS.