What happened?
Summary
The is flagged by our Mend security scan.
authlib>=1.6.11 is a forced dependency of both the client and server extras in fastmcp-slim. authlib (even the latest version 1.8.0) is currently affected by two unpatched, critical (CVE-2026-96760, CVE-2026-104056) CVEs with no fix timeline, and it looks like the own maintainer said the affected module won't be patched.
The vulnerabilities (both are critical)
Both affect the current latest release, authlib 1.8.0 (2026-08-30) — both CVEs were published after that release (2026-09-28 and 2026-10-01 respectively), and no newer authlib version exists on PyPI.
Maintainer response suggests no fix is coming
A community contributor submitted a working fix for CVE-2026-96760 as [authlib/authlib#938](authlib/authlib#938), including a regression test. After a follow-up ping, authlib's maintainer (lepture) replied:
"Please use joserfc module. authlib.jose module is depreciated."
Please check how those critical vulnerabilities can be addressed ASAP
Would it be possible to drop that dependency?
Example Code
Version Information
FastMCP version: 3.2.4
MCP version: 1.28.1
Python version: 3.14.4
Platform: Windows-11-10.0.22631-SP0
What happened?
Summary
The is flagged by our Mend security scan.
authlib>=1.6.11is a forced dependency of both theclientandserverextras infastmcp-slim.authlib(even the latest version 1.8.0) is currently affected by two unpatched, critical (CVE-2026-96760, CVE-2026-104056) CVEs with no fix timeline, and it looks like the own maintainer said the affected module won't be patched.The vulnerabilities (both are critical)
Both affect the current latest release,
authlib1.8.0 (2026-08-30) — both CVEs were published after that release (2026-09-28 and 2026-10-01 respectively), and no newer authlib version exists on PyPI.Maintainer response suggests no fix is coming
A community contributor submitted a working fix for CVE-2026-96760 as [authlib/authlib#938](authlib/authlib#938), including a regression test. After a follow-up ping, authlib's maintainer (
lepture) replied:"Please use joserfc module. authlib.jose module is depreciated."
Please check how those critical vulnerabilities can be addressed ASAP
Would it be possible to drop that dependency?
Example Code
Version Information