Security: bump oauthlib minimum to 4.0.0 (CVE-2026-49264, CVE-2026-49265)

#576 · open · 0 comments

View on GitHub ↗

friedrichwilken

Two CVEs were published against `oauthlib` that affect versions prior to 4.0.0: - **CVE-2026-49265** -- Timing attack vulnerability in PKCE `code_verifier` comparison (CWE-208). The comparison was not constant-time, allowing side-channel leakage of the verifier. - **CVE-2026-49264** -- Unsafe JSONP callback injection in `RevocationEndpoint` allows arbitrary JavaScript response generation. Both are fixed in **oauthlib 4.0.0**. `requests-oauthlib` currently declares `oauthlib>=3.0.0`, which allows resolvers to pick up the vulnerable 3.x releases. Bumping the lower bound to `>=4.0.0` ensures downstream projects are protected. A PR with the one-line fix is attached.

Comments