CVE-2026-41425: Authlib: Cross-site request forging when using cache
(updated )
There is no CSRF protection on the cache feature on most integrations clients.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-41425 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →