Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type (CVE-2026-41479) | HOL Guard CVE