openSUSE Tumbleweed — python310-Authlib — vulnerability — patch and remediation guide
🟠 High ⏱ 15–60 min Last verified: 25 May 2026 Affected versions: openSUSE Tumbleweed 📖 ~4 min read • Source: SUSE advisory SUSE-SU-2024:2064-1 (see also SUSE bugzilla) Related CVEs: CVE-2024-37568 Upstream summary: lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification […]