friedrichwilken
Two CVEs were published against `oauthlib` that affect versions prior to 4.0.0: - **CVE-2026-49265** -- Timing attack vulnerability in PKCE `code_verifier` comparison (CWE-208). The comparison was not constant-time, allowing side-channel leakage of the verifier. - **CVE-2026-49264** -- Unsafe JSONP callback injection in `RevocationEndpoint` allows arbitrary JavaScript response generation. Both are fixed in **oauthlib 4.0.0**. `requests-oauthlib` currently declares `oauthlib>=3.0.0`, which allows resolvers to pick up the vulnerable 3.x releases. Bumping the lower bound to `>=4.0.0` ensures downstream projects are protected. A PR with the one-line fix is attached.