Skip to content

fix(deps): vuln Authlib (minor → 1.7.2) [tests/TestRunner] - #34

Open
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/pip/TestRunner/0-1783352523
Open

fix(deps): vuln Authlib (minor → 1.7.2) [tests/TestRunner]#34
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/pip/TestRunner/0-1783352523

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown

Summary: Critical-severity security update — 1 package upgraded (MINOR changes included)

Manifests changed:

  • tests/TestRunner (pip)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
Authlib 1.1.0 1.7.2 minor Direct 3 CRITICAL, 11 HIGH, 9 MEDIUM

Security Details

🚨 Critical & High Severity (14 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
Authlib PYSEC-2026-287 critical Authlib JWS JWK Header Injection: Signature Verification Bypass 1.1.0 1.6.9 -
Authlib GHSA-wvwj-cvrp-7pv5 CRITICAL Authlib JWS JWK Header Injection: Signature Verification Bypass 1.1.0 1.6.9 -
Authlib CVE-2026-27962 critical Authlib JWS JWK Header Injection: Signature Verification Bypass 1.1.0 - -
Authlib CVE-2024-37568 HIGH - 1.1.0 - -
Authlib PYSEC-2024-52 HIGH - 1.1.0 1.3.1 -
Authlib CVE-2025-61920 HIGH Authlib is vulnerable to Denial of Service via Oversized JOSE Segments 1.1.0 - -
Authlib CVE-2026-28498 HIGH Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding 1.1.0 - -
Authlib GHSA-pq5p-34cr-23v9 HIGH Authlib is vulnerable to Denial of Service via Oversized JOSE Segments 1.1.0 1.6.5 -
Authlib CVE-2025-59420 HIGH Authlib: JWS/JWT accepts unknown crit headers (RFC violation → possible authz bypass) 1.1.0 - -
Authlib GHSA-9ggr-2464-2j32 HIGH Authlib: JWS/JWT accepts unknown crit headers (RFC violation → possible authz bypass) 1.1.0 1.6.4 -
Authlib GHSA-m344-f55w-2m6j HIGH Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding 1.1.0 1.6.9 -
Authlib GHSA-5357-c2jx-v7qh HIGH Authlib has algorithm confusion with asymmetric public keys 1.1.0 1.3.1 -
Authlib GHSA-7432-952r-cw78 HIGH Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle 1.1.0 1.6.9 -
Authlib CVE-2026-28490 HIGH Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle 1.1.0 - -
ℹ️ Other Vulnerabilities (9)
Package CVE Severity Summary Unsafe Version Fixed In Case
Authlib GHSA-w8p2-r796-3vmq MODERATE Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type 1.1.0 1.6.10 -
Authlib GHSA-jj8c-mmj3-mmgv MODERATE Authlib: Cross-site request forging when using cache 1.1.0 1.6.11 -
Authlib CVE-2025-68158 MODERATE Authlib: 1-click Account Takeover 1.1.0 - -
Authlib PYSEC-2026-25 MODERATE - 1.1.0 1.6.11 -
Authlib GHSA-r95x-qfjj-fjj2 MODERATE Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect 1.1.0 1.7.1 -
Authlib PYSEC-2026-188 MODERATE - 1.1.0 1.6.12 -
Authlib GHSA-fg6f-75jq-6523 MODERATE Authlib has 1-click Account Takeover vulnerability 1.1.0 1.6.6 -
Authlib GHSA-g7f3-828f-7h7m MODERATE Authlib : JWE zip=DEF decompression bomb enables DoS 1.1.0 1.6.5 -
Authlib CVE-2025-62706 MODERATE Authlib : JWE zip=DEF decompression bomb enables DoS 1.1.0 - -

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

@dd-prapprover-prod-77c48c

dd-prapprover-prod-77c48c Bot commented Jul 7, 2026

Copy link
Copy Markdown

PRApprover will approve and merge this PR, FAQ, #dx-source-code-management

🛠️ PRApproval Status

  • ✅ PR is eligible for auto-approval by rule dependency-management-version-updater - 2026-07-07T12:46:19Z
  • ⬜ CI tests passed
  • ⬜ Approved
  • ⬜ Merge Started
  • ⬜ Merged

➡️ Current phase: waiting for CI tests to complete...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants