Debian Patches

Status for python-authlib/1.2.0-1+deb12u2

Patch Description Author Forwarded Bugs Origin Last update
sphinx-default-theme Use the default theme
sphinx_typlog_theme isn't packaged in Debian, yet.
Stefano Rivera <stefanor@debian.org> not-needed 2020-08-18
sphinx-3rdparty-assets Disable 3rd party assets in docs
Fetching assets from external websites can cause a privacy breach.
Stefano Rivera <stefanor@debian.org> no 2020-08-18
CVE-2025-62706.patch fix(jose): add max size for JWE zip=DEF decompression Hsiaoming Yang <me@lepture.com> yes upstream https://github.com/authlib/authlib/commit/4b5b5703394608124cd39e547cc7829feda05a13 2025-09-24
CVE-2025-61920.patch fix(jose): add size limitation to prevent DoS Hsiaoming Yang <me@lepture.com> yes upstream https://github.com/authlib/authlib/commit/867e3f87b072347a1ae9cf6983cc8bbf88447e5e 2025-10-02
CVE-2025-59420.patch [PATCH 3/3] fix(jose): Reject unprotected ‘crit’ and enforce type; add tests (#823) Muhammad Noman Ilyas <113287211+AL-Cybision@users.noreply.github.com> yes upstream https://github.com/authlib/authlib/commit/6b1813e4392eb7c168c276099ff7783b176479df 2025-09-14
CVE-2025-68158.patch Merge commit from fork Hsiaoming Yang <me@lepture.com> yes upstream https://github.com/authlib/authlib/commit/2808378611dd6fb2532b189a9087877d8f0c0489 2025-12-12
CVE-2024-37568.patch fix: prevent OctKey to import ssh/rsa/pem keys
https://github.com/lepture/authlib/issues/654
Hsiaoming Yang <me@lepture.com> yes upstream https://github.com/lepture/authlib/commit/3bea812acefebc9ee108aa24557be3ba8971daf1 2024-06-04
CVE-2026-44681.patch fix: redirecting to unvalidated redirect_uri on InvalidScopeError in OIDC grants Éloi Rivard <eloi@yaal.coop> no backport, https://github.com/authlib/authlib/commit/7b4ecd7c88ac96ba7b759187a4b6d109d9031ee0 2026-05-02
CVE-2026-27962.patch fix(jose): do not use header's jwk automatically Hsiaoming Yang <me@lepture.com> no upstream, https://github.com/authlib/authlib/commit/a5d4b2d4c9e46bfa11c82f85fdc2bcc0b50ae681 2026-02-25
CVE-2026-28490.patch fix(jose): remove deprecated algorithm from default registry Hsiaoming Yang <me@lepture.com> no upstream, https://github.com/authlib/authlib/commit/48b345f29f6c459f11c6a40162b6c0b742ef2e22 2026-02-26
CVE-2026-28498.patch fix(oidc): fail close at validating c_hash and at_hash Hsiaoming Yang <me@lepture.com> no backport, https://github.com/authlib/authlib/commit/b9bb2b25bf8b7e01512d847a95c1749646eaa72b 2026-03-01
CVE-2026-41425-0.patch Fix ever-growing session size Wauplin <lucainp@gmail.com> no upstream, https://github.com/authlib/authlib/commit/01efd157bb8de6f90487b85f91fdd5e46fafa6d7 2024-04-11
CVE-2026-41425-1.patch fix: CSRF issue with starlette client Éloi Rivard <eloi@yaal.coop> no backport, https://github.com/authlib/authlib/commit/401a7709c3fe43bce1b2105d16a475b688faa788 2026-04-15

All known versions for source package 'python-authlib'

Links