CVE-2026-28490

unknown
Published 2026-03-16 · Modified 2026-04-21
CVSS v3
CVSS v2
VIR risk

Description

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a cryptographic padding oracle vulnerability was identified in the Authlib Python library concerning the implementation of the JSON Web Encryption (JWE) RSA1_5 key management algorithm. Authlib registers RSA1_5 in its default algorithm registry without requiring explicit opt-in, and actively destroys the constant-time Bleichenbacher mitigation that the underlying cryptography library implements correctly. This issue has been patched in version 1.6.9.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-28490

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2026-28490.html

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormaffected
debian debianbullseyefixed0.15.4-1+deb11u2
debian debianforkyfixed1.6.9-1
debian debiansidfixed1.6.9-1
debian debiantrixieaffected

Package impact

EcosystemPackageVulnerableFixed
python PyPIauthlib<1.6.91.6.9

References

Verify integrity in audit chain (admin only). AS-IS.