External risk intelligence

Authlib Metadata Caching Vulnerability Allows Endpoint Hijacking.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-104056

Authlib is a library used extensively in web applications and API services to implement OAuth and OpenID Connect. Because these components are frequently deployed as internet-facing authentication and identity endpoints, the vulnerable discovery metadata processing is commonly reachable from the public internet.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in Authlib, a library used for authentication and identity services. The issue involves improper handling of discovery metadata, which could allow an attacker to redirect authentication requests to malicious endpoints rather than legitimate ones. The main concern is confirming if our deployed services utilize Authlib and are thus exposed.

  • Unvalidated metadata can redirect authentication.
  • Confirms if Authlib is used and exposed.
  • Verify relevance and exposure to Authlib.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted discovery JSON to a vulnerable application. Because the application caches this metadata without proper validation and origin checks, it may replace legitimate endpoint URLs with attacker-controlled ones. This could allow an attacker to redirect users to malicious sites or intercept sensitive information.

  • Unauthenticated access to a vulnerable application.
  • Tricking the application into processing a malicious discovery response.
  • Execution of arbitrary code or data manipulation.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, this vulnerability could allow an attacker to manipulate endpoint values used in authentication and authorization flows. This is possible when the discovery JSON metadata is cached without proper validation or issuer-origin binding, enabling a poisoned response to redirect requests to attacker-controlled endpoints.

  • Authentication and authorization endpoints.
  • Poisoned discovery responses.
  • Compromised service interactions.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability, impacting Authlib's discovery metadata processing, requires immediate attention from teams managing authentication and identity services, likely application owners and platform teams. The first step is to identify all instances of the affected technology, determine their reachability and criticality, and then confirm the accountable owner to plan remediation.

  • Application and platform teams should own the issue.
  • Verify external reachability and metadata origin.
  • Plan and coordinate timely remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Authlib and why is it used?

Authlib is a software library designed to help developers build authentication and identity features in web applications. It is frequently employed to implement OAuth and OpenID Connect protocols, which manage how users log in and how different services securely share data.

What does CWE-345 and CWE-346 mean for CVE-2026-104056?

These codes refer to improper validation of integrity and origin. In this CVE, it means the software fails to verify that the discovery information it receives actually comes from a trusted source. Because it lacks this check, the application unknowingly accepts and saves fraudulent data, allowing it to be tricked about where it should send authentication traffic.

How does an attacker trigger this vulnerability?

An attacker triggers this by feeding the application a malicious discovery JSON file. The system will not be affected if it only processes metadata from pre-approved, static, or local configuration files that cannot be influenced by external network traffic or user-provided input.

Do I need to worry if my service is internal?

According to Halo Surface Signal, this vulnerability is particularly concerning for internet-facing authentication endpoints. While internal services remain potentially susceptible to attackers who have already gained a foothold on your network, the risk is highest for systems directly reachable from the public internet.

When should I take action for this CVE?

You should begin by identifying which of your applications use Authlib and determining if they handle discovery metadata. Once mapped, focus on those exposed to the internet. Prioritize verifying if your current implementation allows for the dynamic caching of discovery responses, as this is the primary behavior facilitating the redirect.

References