critical
Security update for python-authlib
SUSE-SLE-Module-Python3-15-SP7-2026-975
This update for python-Authlib fixes the following issues: - CVE-2026-27962: JWS `deserialize_compact()` allows for signature bypass by accepting user-controlled embedded JWK as verification key (bsc#1259738). - CVE-2026-28490: cryptographic padding oracle in JWE RSA1_5 key management algorithm (bsc#1259736). - CVE-2026-28498: fail-open in behavior OIDC hash validation allows for bypass mandatory integrity protections (bsc#1259737).
-
Release DateMar 23 2026
-
References
-
Typesecurity
-
Severitycritical
cloud_download Downloads
To download packages, you need to log in and have a valid subscription.
Python 3 Module 15.7 aarch64
-
Packagespython-Authlib
Python library for building OAuth and OpenID Connect serverspython311-Authlib1.3.1-150600.3.17.1 lock src
Python library for building OAuth and OpenID Connect servers1.3.1-150600.3.17.1 lock rpm
Python 3 Module 15.7 ppc64le
-
Packagespython-Authlib
Python library for building OAuth and OpenID Connect serverspython311-Authlib1.3.1-150600.3.17.1 lock src
Python library for building OAuth and OpenID Connect servers1.3.1-150600.3.17.1 lock rpm
Python 3 Module 15.7 x86_64
-
Packagespython-Authlib
Python library for building OAuth and OpenID Connect serverspython311-Authlib1.3.1-150600.3.17.1 lock src
Python library for building OAuth and OpenID Connect servers1.3.1-150600.3.17.1 lock rpm