<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:04:40 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-04354</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-04354</link>
      <description>bdu:2026-04354</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-04354</guid>
    </item>
    <item>
      <title>BREW-fastmcp-CVE-2026-28498 — Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding</title>
      <link>https://cve.radiocsirt.org/vuln/brew-fastmcp-cve-2026-28498</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: fastmcp&lt;/p&gt;
&lt;p&gt;## 1. Executive Summary&lt;/p&gt;
&lt;p&gt;A critical library-level vulnerability was identified in the **Authlib** Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (`_verify_hash`) responsible for validating the `at_hash` (Access Token Hash) and `c_hash` (Authorization Code Hash) claims exhibits a **fail-open** behavior when encountering an unsupported or unknown cryptographic algorithm.&lt;/p&gt;
&lt;p&gt;This flaw allows an attacker to bypass mandatory integrity protections by supplying a forged ID Token with a deliberately unrecognized `alg` header parameter. The library intercepts the unsupported state and silently returns `True` (validation passed), inherently violating fundamental cryptographic design principles and direct OIDC specifications.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 2. Technical Details &amp;amp; Root Cause&lt;/p&gt;
&lt;p&gt;The vulnerability resides within the `_verify_hash(signature, s, alg)` function in `authlib/oidc/core/claims.py`:&lt;/p&gt;
&lt;p&gt;```python
def _verify_hash(signature, s, alg):
    hash_value = create_half_hash(s, alg)
    if not hash_value:        # ← VULNERABILITY: create_half_hash returns None for unknown algorithms
        return True            # ← BYPASS: The verification silently passes
    return hmac.compare_digest(hash_value, to_bytes(signature))
```&lt;/p&gt;
&lt;p&gt;When an unsupported algorithm string (e.g., `&amp;#34;XX999&amp;#34;`) is processed by the helper function `create_half_hash` in `authlib/oidc/core/util.py`, the internal `getattr(hashlib, hash_type, None)` call fai…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: fastmcp&lt;/p&gt;
&lt;p&gt;## 1. Executive Summary&lt;/p&gt;
&lt;p&gt;A critical library-level vulnerability was identified in the **Authlib** Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (`_verify_hash`) responsible for validating the `at_hash` (Access Token Hash) and `c_hash` (Authorization Code Hash) claims exhibits a **fail-open** behavior when encountering an unsupported or unknown cryptographic algorithm.&lt;/p&gt;
&lt;p&gt;This flaw allows an attacker to bypass mandatory integrity protections by supplying a forged ID Token with a deliberately unrecognized `alg` header parameter. The library intercepts the unsupported state and silently returns `True` (validation passed), inherently violating fundamental cryptographic design principles and direct OIDC specifications.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 2. Technical Details &amp;amp; Root Cause&lt;/p&gt;
&lt;p&gt;The vulnerability resides within the `_verify_hash(signature, s, alg)` function in `authlib/oidc/core/claims.py`:&lt;/p&gt;
&lt;p&gt;```python
def _verify_hash(signature, s, alg):
    hash_value = create_half_hash(s, alg)
    if not hash_value:        # ← VULNERABILITY: create_half_hash returns None for unknown algorithms
        return True            # ← BYPASS: The verification silently passes
    return hmac.compare_digest(hash_value, to_bytes(signature))
```&lt;/p&gt;
&lt;p&gt;When an unsupported algorithm string (e.g., `&amp;#34;XX999&amp;#34;`) is processed by the helper function `create_half_hash` in `authlib/oidc/core/util.py`, the internal `getattr(hashlib, hash_type, None)` call fai…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-fastmcp-cve-2026-28498</guid>
    </item>
    <item>
      <title>EUVD-2026-366073</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366073</link>
      <description>EUVD-2026-366073</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366073</guid>
    </item>
    <item>
      <title>fkie_cve-2026-28498</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-28498</link>
      <description>&lt;p&gt;Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (_verify_hash) responsible for validating the at_hash (Access Token Hash) and c_hash (Authorization Code Hash) claims exhibits a fail-open behavior when encountering an unsupported or unknown cryptographic algorithm. This flaw allows an attacker to bypass mandatory integrity protections by supplying a forged ID Token with a deliberately unrecognized alg header parameter. The library intercepts the unsupported state and silently returns True (validation passed), inherently violating fundamental cryptographic design principles and direct OIDC specifications. This issue has been patched in version 1.6.9.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (_verify_hash) responsible for validating the at_hash (Access Token Hash) and c_hash (Authorization Code Hash) claims exhibits a fail-open behavior when encountering an unsupported or unknown cryptographic algorithm. This flaw allows an attacker to bypass mandatory integrity protections by supplying a forged ID Token with a deliberately unrecognized alg header parameter. The library intercepts the unsupported state and silently returns True (validation passed), inherently violating fundamental cryptographic design principles and direct OIDC specifications. This issue has been patched in version 1.6.9.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-28498</guid>
    </item>
    <item>
      <title>GHSA-m344-f55w-2m6j — Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m344-f55w-2m6j</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: authlib&lt;/p&gt;
&lt;p&gt;## 1. Executive Summary&lt;/p&gt;
&lt;p&gt;A critical library-level vulnerability was identified in the **Authlib** Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (`_verify_hash`) responsible for validating the `at_hash` (Access Token Hash) and `c_hash` (Authorization Code Hash) claims exhibits a **fail-open** behavior when encountering an unsupported or unknown cryptographic algorithm.&lt;/p&gt;
&lt;p&gt;This flaw allows an attacker to bypass mandatory integrity protections by supplying a forged ID Token with a deliberately unrecognized `alg` header parameter. The library intercepts the unsupported state and silently returns `True` (validation passed), inherently violating fundamental cryptographic design principles and direct OIDC specifications.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 2. Technical Details &amp;amp; Root Cause&lt;/p&gt;
&lt;p&gt;The vulnerability resides within the `_verify_hash(signature, s, alg)` function in `authlib/oidc/core/claims.py`:&lt;/p&gt;
&lt;p&gt;```python
def _verify_hash(signature, s, alg):
    hash_value = create_half_hash(s, alg)
    if not hash_value:        # ← VULNERABILITY: create_half_hash returns None for unknown algorithms
        return True            # ← BYPASS: The verification silently passes
    return hmac.compare_digest(hash_value, to_bytes(signature))
```&lt;/p&gt;
&lt;p&gt;When an unsupported algorithm string (e.g., `&amp;#34;XX999&amp;#34;`) is processed by the helper function `create_half_hash` in `authlib/oidc/core/util.py`, the internal `getattr(hashlib, hash_type, None)` call fai…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: authlib&lt;/p&gt;
&lt;p&gt;## 1. Executive Summary&lt;/p&gt;
&lt;p&gt;A critical library-level vulnerability was identified in the **Authlib** Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (`_verify_hash`) responsible for validating the `at_hash` (Access Token Hash) and `c_hash` (Authorization Code Hash) claims exhibits a **fail-open** behavior when encountering an unsupported or unknown cryptographic algorithm.&lt;/p&gt;
&lt;p&gt;This flaw allows an attacker to bypass mandatory integrity protections by supplying a forged ID Token with a deliberately unrecognized `alg` header parameter. The library intercepts the unsupported state and silently returns `True` (validation passed), inherently violating fundamental cryptographic design principles and direct OIDC specifications.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## 2. Technical Details &amp;amp; Root Cause&lt;/p&gt;
&lt;p&gt;The vulnerability resides within the `_verify_hash(signature, s, alg)` function in `authlib/oidc/core/claims.py`:&lt;/p&gt;
&lt;p&gt;```python
def _verify_hash(signature, s, alg):
    hash_value = create_half_hash(s, alg)
    if not hash_value:        # ← VULNERABILITY: create_half_hash returns None for unknown algorithms
        return True            # ← BYPASS: The verification silently passes
    return hmac.compare_digest(hash_value, to_bytes(signature))
```&lt;/p&gt;
&lt;p&gt;When an unsupported algorithm string (e.g., `&amp;#34;XX999&amp;#34;`) is processed by the helper function `create_half_hash` in `authlib/oidc/core/util.py`, the internal `getattr(hashlib, hash_type, None)` call fai…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m344-f55w-2m6j</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:20392-1 — Security update for python-Authlib</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:20392-1</link>
      <description>&lt;p&gt;Security update for python-Authlib&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-Authlib&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:20392-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-2117</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2117</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: authlib&lt;/p&gt;
&lt;p&gt;Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (_verify_hash) responsible for validating the at_hash (Access Token Hash) and c_hash (Authorization Code Hash) claims exhibits a fail-open behavior when encountering an unsupported or unknown cryptographic algorithm. This flaw allows an attacker to bypass mandatory integrity protections by supplying a forged ID Token with a deliberately unrecognized alg header parameter. The library intercepts the unsupported state and silently returns True (validation passed), inherently violating fundamental cryptographic design principles and direct OIDC specifications. This issue has been patched in version 1.6.9.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: authlib&lt;/p&gt;
&lt;p&gt;Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (_verify_hash) responsible for validating the at_hash (Access Token Hash) and c_hash (Authorization Code Hash) claims exhibits a fail-open behavior when encountering an unsupported or unknown cryptographic algorithm. This flaw allows an attacker to bypass mandatory integrity protections by supplying a forged ID Token with a deliberately unrecognized alg header parameter. The library intercepts the unsupported state and silently returns True (validation passed), inherently violating fundamental cryptographic design principles and direct OIDC specifications. This issue has been patched in version 1.6.9.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2117</guid>
    </item>
    <item>
      <title>RHSA-2026:6309 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.6 Container Release Update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:6309</link>
      <description>&lt;p&gt;aiohttp: AIOHTTP&amp;#39;s HTTP Parser auto_decompress feature is vulnerable to zip bomb ajv: ReDoS via $data reference jsonpath: jsonpath: Arbitrary Code Execution via unsafe JSON Path expression evaluation axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves authlib: Authlib: Authentication bypass via forged OpenID Connect ID Tokens authlib: Authlib: Signature verification bypass via malicious JWT allows unauthorized access svgo: SVGO: Denial of Service via XML entity expansion express-rate-limit: express-rate-limit: Denial of Service for IPv4 clients due to incorrect IPv6 subnet masking pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;aiohttp: AIOHTTP&amp;#39;s HTTP Parser auto_decompress feature is vulnerable to zip bomb ajv: ReDoS via $data reference jsonpath: jsonpath: Arbitrary Code Execution via unsafe JSON Path expression evaluation axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves authlib: Authlib: Authentication bypass via forged OpenID Connect ID Tokens authlib: Authlib: Signature verification bypass via malicious JWT allows unauthorized access svgo: SVGO: Denial of Service via XML entity expansion express-rate-limit: express-rate-limit: Denial of Service for IPv4 clients due to incorrect IPv6 subnet masking pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:6309</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-28498</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-28498</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:22.04:LTS: python-authlib, Ubuntu:Pro:24.04:LTS: python-authlib, Ubuntu:25.10: python-authlib, Ubuntu:Pro:26.04:LTS: python-authlib&lt;/p&gt;
&lt;p&gt;Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (_verify_hash) responsible for validating the at_hash (Access Token Hash) and c_hash (Authorization Code Hash) claims exhibits a fail-open behavior when encountering an unsupported or unknown cryptographic algorithm. This flaw allows an attacker to bypass mandatory integrity protections by supplying a forged ID Token with a deliberately unrecognized alg header parameter. The library intercepts the unsupported state and silently returns True (validation passed), inherently violating fundamental cryptographic design principles and direct OIDC specifications. This issue has been patched in version 1.6.9.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:22.04:LTS: python-authlib, Ubuntu:Pro:24.04:LTS: python-authlib, Ubuntu:25.10: python-authlib, Ubuntu:Pro:26.04:LTS: python-authlib&lt;/p&gt;
&lt;p&gt;Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concerning the validation of OpenID Connect (OIDC) ID Tokens. Specifically, the internal hash verification logic (_verify_hash) responsible for validating the at_hash (Access Token Hash) and c_hash (Authorization Code Hash) claims exhibits a fail-open behavior when encountering an unsupported or unknown cryptographic algorithm. This flaw allows an attacker to bypass mandatory integrity protections by supplying a forged ID Token with a deliberately unrecognized alg header parameter. The library intercepts the unsupported state and silently returns True (validation passed), inherently violating fundamental cryptographic design principles and direct OIDC specifications. This issue has been patched in version 1.6.9.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-28498</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0935 — Red Hat Ansible Automation Platform: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0935</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um einen Denial of Service Angriff durchzuführen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Red Hat Ansible Automation Platform ausnutzen, um einen Denial of Service Angriff durchzuführen, beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder Cross-Site-Scripting-Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0935</guid>
    </item>
  </channel>
</rss>
