-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 29 Jul 2026 08:21:40 +0200 Source: python-authlib Architecture: source Version: 0.15.4-1+deb11u3 Distribution: bullseye-security Urgency: high Maintainer: Debian Python Team <team+python@tracker.debian.org> Changed-By: Andrej Shadura <andrewsh@debian.org> Changes: python-authlib (0.15.4-1+deb11u3) bullseye-security; urgency=high . * Non-maintainer upload by the LTS Team. * Backport upstream patch for CVE-2026-44681: - Always unvalidate redirect URI when raisung InvalidScopeError in OIDC grants. Checksums-Sha1: 6fc8f5c775b281e81a14102f5e0435f560df3930 1933 python-authlib_0.15.4-1+deb11u3.dsc 65f37ef02b1834b6858f014da8e3653687f82817 273443 python-authlib_0.15.4.orig.tar.gz 72cbaf1193d548141ae1c08892ab99a531503ae5 12496 python-authlib_0.15.4-1+deb11u3.debian.tar.xz ae9a40b24acd5a7c0da02cd75f01f1e276bb8211 7976 python-authlib_0.15.4-1+deb11u3_source.buildinfo Checksums-Sha256: 98583175b302930ffa91017e505ee6438e21057cbc280fd8387db2579d997aea 1933 python-authlib_0.15.4-1+deb11u3.dsc 9724a1ff0116a661213dc892e32af72c45ee2b3ee2c93edebc53a5f9dd94c50d 273443 python-authlib_0.15.4.orig.tar.gz 613aa2e27713f961ac232c7331284105128eda45a63af314fd1fe49dbea3011b 12496 python-authlib_0.15.4-1+deb11u3.debian.tar.xz 2b2917422658de56be53ec8ece23d18fca30258bea9e4662eac3d201d8c5f7c9 7976 python-authlib_0.15.4-1+deb11u3_source.buildinfo Files: 30048bf01c5d7b37f32bf701e06fdc4a 1933 python optional python-authlib_0.15.4-1+deb11u3.dsc 9adc317946e60630a5e2859cab8d5a73 273443 python optional python-authlib_0.15.4.orig.tar.gz ce19f2c433534ae11f88c3f4b96df4a9 12496 python optional python-authlib_0.15.4-1+deb11u3.debian.tar.xz 2993bbad3187d81ee61a68f7ccb02ecd 7976 python optional python-authlib_0.15.4-1+deb11u3_source.buildinfo -----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQSD3NF/RLIsyDZW7aHoRGtKyMdyYQUCamm1twAKCRDoRGtKyMdy YRZcAP92+lqtg9FNQjPgZVEqfCRHOLJcHsCCxsH00b+l+6JijQEAsRU0ACxLiS2i vcgkJzgqAZ7areI/EkbD95loeeyAqgw= =01Gk -----END PGP SIGNATURE-----