[pkg-vuln] CVE-2026-49264 in oauthlib@3.3.1 #890
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Severity: MEDIUM
Package:
oauthlib@3.3.1Fixed in:
4.0.0Summary
When
enable_jsonp=True, oauthlib'sRevocationEndpointreflects the user-suppliedcallbackparameter directly into JavaScript response bodies on both success and error paths without validating that it is a legal JSONP callback name. This allows arbitrary JavaScript response generation instead of a restricted function call, making the documented JSONP revocation feature unsafe for browser-based JSONP consumption when attackers can influencecallback.Details
The issue is
Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-49264