CVE-2026-104056
Summary
| CVE | CVE-2026-104056 |
|---|---|
| State | PUBLISHED |
| Assigner | certcc |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-10-01 19:17:19 UTC |
| Updated | 2026-10-01 20:37:42 UTC |
| Description | Authlib version 1.7.2 and below contains a vulnerability where discovery JSON metadata is cached without validation or issuer-origin binding. This allows a poisoned discovery response to replace all endpoint values with attacker-controlled values rather than endpoint URLs that share the origin of the configured server metadata URL. |
Risk And Classification
Problem Types: CWE-345 Insufficient Verification of Data Authenticity | CWE-346 Origin Validation Error | CWE-829 Inclusion of Functionality from Untrusted Control Sphere
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| uziii2208.github.io/post/cve-2026-104056 | [email protected] | uziii2208.github.io | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.