critical Security update for python-authlib
SUSE-SLE-Module-Python3-15-SP7-2026-975


This update for python-Authlib fixes the following issues: - CVE-2026-27962: JWS `deserialize_compact()` allows for signature bypass by accepting user-controlled embedded JWK as verification key (bsc#1259738). - CVE-2026-28490: cryptographic padding oracle in JWE RSA1_5 key management algorithm (bsc#1259736). - CVE-2026-28498: fail-open in behavior OIDC hash validation allows for bypass mandatory integrity protections (bsc#1259737).


cloud_download Downloads

Python 3 Module 15.7 aarch64
  • Packages
    python-Authlib
    Python library for building OAuth and OpenID Connect servers
    1.3.1-150600.3.17.1 lock src
    python311-Authlib
    Python library for building OAuth and OpenID Connect servers
    1.3.1-150600.3.17.1 lock rpm
Python 3 Module 15.7 ppc64le
  • Packages
    python-Authlib
    Python library for building OAuth and OpenID Connect servers
    1.3.1-150600.3.17.1 lock src
    python311-Authlib
    Python library for building OAuth and OpenID Connect servers
    1.3.1-150600.3.17.1 lock rpm
Python 3 Module 15.7 x86_64
  • Packages
    python-Authlib
    Python library for building OAuth and OpenID Connect servers
    1.3.1-150600.3.17.1 lock src
    python311-Authlib
    Python library for building OAuth and OpenID Connect servers
    1.3.1-150600.3.17.1 lock rpm