vulns.co
/
GKData.io MCP

Authlib · 1 min read

Authlib: error responses must preserve redirect-destination validation

CVE-2026-44681 describes an OIDC error path selecting a response destination before client and destination validation. The maintainer reports an unauthorized browser redirect, explicitly excluding direct disclosure of authorization codes or tokens. The failed boundary was untrusted request data becoming trusted error-response routing.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

Editorial reasoning: an exception can exercise authority even when the main operation fails. Establish destination trust before producing redirect-capable errors, and review rejection paths across grant implementations. The official v1.6.12 release notes corroborate the validation correction.

Before reading

  • Identity-provider integration and authorization concepts

Context and limits

  • Exposure requires an affected server supporting implicit or hybrid OIDC grants; the advisory excludes code-only configurations from this variant. Authentication is unnecessary, but browser redirection requires user interaction. Phishing consequences are possible downstream harm, not demonstrated account compromise.
  • The advisory identifies 1.6.12 and 1.7.1 as patched. Software versions are not resource editions; exact patch-release dates remain unrecorded.
  • azmeuk published the advisory; y011d4 is credited as Reporter. The reviewed advisory has no explicit narrative byline, so authors is empty; publication and reporting credits do not by themselves establish who wrote the narrative. No bounty qualification or independent reproduction is established.

Sources and provenance

  1. Open Redirect in Authlib OIDC Implicit/Hybrid Authorization Authlib · reviewed 2026-10-03
  2. Release v1.6.12 Authlib · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software