Skip to content

authlib dependency has 2 unpatched critical CVEs with no fix planned #5531

Description

@zhuweid

What happened?

Summary

The is flagged by our Mend security scan.

authlib>=1.6.11 is a forced dependency of both the client and server extras in fastmcp-slim. authlib (even the latest version 1.8.0) is currently affected by two unpatched, critical (CVE-2026-96760, CVE-2026-104056) CVEs with no fix timeline, and it looks like the own maintainer said the affected module won't be patched.

The vulnerabilities (both are critical)

Both affect the current latest release, authlib 1.8.0 (2026-08-30) — both CVEs were published after that release (2026-09-28 and 2026-10-01 respectively), and no newer authlib version exists on PyPI.

Maintainer response suggests no fix is coming

A community contributor submitted a working fix for CVE-2026-96760 as [authlib/authlib#938](authlib/authlib#938), including a regression test. After a follow-up ping, authlib's maintainer (lepture) replied:

"Please use joserfc module. authlib.jose module is depreciated."

Please check how those critical vulnerabilities can be addressed ASAP

Would it be possible to drop that dependency?

Example Code

Version Information

FastMCP version:                                                                 3.2.4
MCP version:                                                                    1.28.1
Python version:                                                                 3.14.4
Platform:                                                    Windows-11-10.0.22631-SP0

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    authRelated to authentication (Bearer, JWT, OAuth, WorkOS) for client or server.bugSomething isn't working. Reports of errors, unexpected behavior, or broken functionality.high-prioritysecuritySecurity fixes: input validation, SSRF/LFI prevention, auth hardening, injection defenses.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions