Pypi · Oauthlib · CVE-2026-41425
**Name of the Vulnerable Software and Affected Versions**
Authlib versions prior to 1.6.11
**Description**
Authlib is a Python library used to build OAuth and OpenID Connect servers. A lack of Cross-Site Request Forgery (CSRF) protection exists in the cache feature of the 'authlib.integrations.starlette client.OAuth' component. CSRF is a type of attack that tricks a victim into submitting a malicious request.
**Recommendations**
Update to version 1.6.11.