DEBIAN-CVE-2025-61920

    Dashboard / Vulnerabilities / DEBIAN-CVE-2025-61920

    DEBIAN-CVE-2025-61920

    Published: 10 Oct 2025Last Modified: 1 Sept 2026
    Upstream:

    Summary:

    Details: Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JWS/JWT header and signature segments. A remote attacker can craft a token whose base64url‑encoded header or signature spans hundreds of megabytes. During verification, Authlib decodes and parses the full input before it is rejected, driving CPU and memory consumption to hostile levels and enabling denial of service. Version 1.6.5 patches the issue. Some temporary workarounds are available. Enforce input size limits before handing tokens to Authlib and/or use application-level throttling to reduce amplification risk.

    Affected packages

    Package

    Name: python-authlib

    Purl: pkg:deb/debian/python-authlib?arch=source&distro=bookworm

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.2.0-1+deb12u1

    Affected versions

    1.2.0-1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    DEBIAN-CVE-2025-61920 | CVE-DB