[pkg-vuln] CVE-2026-49264 in oauthlib@3.3.1 #890

Open
opened 2026-09-30 06:01:57 +00:00 by kert · 0 comments
Owner

Severity: MEDIUM
Package: oauthlib @ 3.3.1
Fixed in: 4.0.0

Summary

When enable_jsonp=True, oauthlib's RevocationEndpoint reflects the user-supplied callback parameter directly into JavaScript response bodies on both success and error paths without validating that it is a legal JSONP callback name. This allows arbitrary JavaScript response generation instead of a restricted function call, making the documented JSONP revocation feature unsafe for browser-based JSONP consumption when attackers can influence callback.

Details

The issue is

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-49264

**Severity:** MEDIUM **Package:** `oauthlib` @ `3.3.1` **Fixed in:** `4.0.0` ### Summary When `enable_jsonp=True`, oauthlib's `RevocationEndpoint` reflects the user-supplied `callback` parameter directly into JavaScript response bodies on both success and error paths without validating that it is a legal JSONP callback name. This allows arbitrary JavaScript response generation instead of a restricted function call, making the documented JSONP revocation feature unsafe for browser-based JSONP consumption when attackers can influence `callback`. ### Details The issue is **Reference:** https://nvd.nist.gov/vuln/detail/CVE-2026-49264
kert added this to the P21: Package Supply Chain — inventory, mirrors, drift, vuln scanning milestone 2026-09-30 06:01:57 +00:00
kert added the qualityci labels 2026-09-30 06:01:57 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: homelab/stack#890