This update for python-Authlib fixes the following issues
CVE-2026-41425: Prior to 1.6.11, there is no CSRF protection on the cache feature in
authlib.integrations.starlette_client.OAuth (bsc#1263114).
CVE-2026-44681: Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's OpenIDImplicitGrant and
OpenIDHybridGrant authorization endpoint exists (bsc#1266665).
Affected Packages
python311-Authlib
SUSE Linux Enterprise Desktop 15 SP7SUSE Linux Enterprise High Performance Computing 15 SP7SUSE Linux Enterprise Module for Python 3 15 SP7SUSE Linux Enterprise Server 15 SP7SUSE Linux Enterprise Server for SAP Applications 15 SP7