
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68158 is a Cross-Site Request Forgery (CSRF) vulnerability in Authlib, a Python library for building OAuth and OpenID Connect servers and clients. When cache-backed state/request-token storage is configured, the FrameworkIntegration.set_state_data function stores the OAuth state blob without binding it to the initiating user session, and get_state_data ignores the caller's session entirely — enabling a "1-click Account Takeover" attack. Affected versions are 1.0.0 through 1.6.5; version 1.6.6 contains the fix. The GitHub Advisory Database rates this Moderate at CVSS v3.1 score of 5.7, while Feedly's aggregated data reflects a score of 8.8 (High) from an alternate scoring perspective (Github Advisory, Authlib Security Advisory).
The root cause is CWE-352 (Cross-Site Request Forgery): when a cache backend (e.g., Redis, Memcached) is supplied to the OAuth client registry, the state blob is stored under the key _state_{app}_{state} in the cache without any session-binding. The get_state_data method retrieves this value purely by the opaque state string, ignoring which user session initiated the flow — violating the OAuth 2.0 RFC 6749 §10.12 requirement that the state parameter be tied to the user-agent session. An attacker who initiates their own OAuth flow can obtain a valid state value, then trick a victim into visiting a crafted callback URL containing the attacker's state and authorization code; Authlib processes the callback without verifying session ownership, completing the token exchange with the attacker's authorization code (Github Advisory, Authlib Security Advisory).
Successful exploitation enables a one-click account takeover: if the target application links SSO identities to existing accounts upon callback (a common pattern), the attacker's SSO account becomes permanently linked to the victim's account, granting full unauthorized access. The primary impact is high confidentiality loss (access to the victim's account data and resources); integrity and availability impacts depend on the application's post-authentication logic. Only applications using Authlib with a cache-backed state storage configuration are affected — those using session-only storage are not vulnerable (Github Advisory, Authlib Security Advisory).
A proof-of-concept exploit scenario is publicly documented in the GitHub Security Advisory, reported by the Snyk Security Labs team (researcher davidbors-snyk). There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.017% (4th percentile), indicating a low near-term exploitation probability. Exploitation requires user interaction (victim must click a crafted link) and the attacker must have a valid state token, which is trivially obtainable by initiating their own OAuth flow (Github Advisory, Authlib Security Advisory).
state value and store it in the shared cache under _state_{app}_{state}.state parameter from the redirect URL. The attacker then completes the OAuth flow with their identity provider to obtain a valid authorization code tied to their own SSO account.state and code values (e.g., https://target.app/callback?code=ATTACKER_CODE&state=ATTACKER_STATE).get_state_data retrieves the state from cache without verifying the victim's session, the callback is processed successfully. The attacker's authorization code is exchanged, and if the application links SSO identities on callback, the attacker's SSO account is permanently linked to the victim's account — granting the attacker full access (Github Advisory, Authlib Security Advisory).state parameter does not correspond to any active session for the requesting user; callback requests originating from IP addresses or user agents inconsistent with the session that initiated the OAuth flow./callback, /oauth/callback, or equivalent) receiving GET requests with state and code parameters from users who have no corresponding pending OAuth authorization in their session._state_{app}_{state} keys in the cache backend being accessed by sessions other than the one that created them (detectable via cache access logging if enabled).Upgrade Authlib to version 1.6.6 or later, which resolves the issue by storing a session-bound marker alongside the cache entry: set_state_data now also writes a lightweight expiry record into the user's session, and get_state_data checks for this session record before retrieving from cache — ensuring the state is always tied to the initiating session (Github Advisory, Patch Commit). As a temporary workaround for applications that cannot immediately upgrade, consider switching from cache-backed state storage to session-only storage by removing the cache configuration from the OAuth client registry. Additionally, review application logic for any account-linking behavior triggered on OAuth callback, and add application-level session validation as a defense-in-depth measure.
The vulnerability was discovered and reported by the Snyk Security Labs team (researcher davidbors-snyk), who disclosed it responsibly to the Authlib maintainers. The advisory was published by maintainer lepture on January 8, 2026. Ubuntu issued security notice USN-8065-1 addressing this CVE, and openSUSE published a security announcement as well, indicating broad Linux distribution uptake of the fix (Ubuntu Advisory, openSUSE Announcement). A technical write-up titled "1-click Account Takeover" was published at infinitsec.net shortly after disclosure.
Fix availability across major Linux distributions and their releases.
bookworm
python-authlib: 1.2.0-1+deb12u1
sid
python-authlib: 1.6.6-1
trixie
python-authlib: 1.6.0-1+deb13u1
devel
python-authlib
jammy
python-authlib
jammy (esm-apps)
python-authlib
noble
python-authlib
noble (esm-apps)
python-authlib: 1.3.0-1ubuntu0.1~esm1
resolute
python-authlib
resolute (esm-apps)
python-authlib
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."