How to use this reference
Editorial reasoning: an exception can exercise authority even when the main operation fails. Establish destination trust before producing redirect-capable errors, and review rejection paths across grant implementations. The official v1.6.12 release notes corroborate the validation correction.
Before reading
- Identity-provider integration and authorization concepts
Context and limits
- Exposure requires an affected server supporting implicit or hybrid OIDC grants; the advisory excludes code-only configurations from this variant. Authentication is unnecessary, but browser redirection requires user interaction. Phishing consequences are possible downstream harm, not demonstrated account compromise.
- The advisory identifies 1.6.12 and 1.7.1 as patched. Software versions are not resource editions; exact patch-release dates remain unrecorded.
- azmeuk published the advisory; y011d4 is credited as Reporter. The reviewed advisory has no explicit narrative byline, so authors is empty; publication and reporting credits do not by themselves establish who wrote the narrative. No bounty qualification or independent reproduction is established.
Sources and provenance
- Open Redirect in Authlib OIDC Implicit/Hybrid Authorization Authlib · reviewed 2026-10-03
- Release v1.6.12 Authlib · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.