[pkg-vuln] CVE-2026-49265 in oauthlib@3.3.1 #891

Open
opened 2026-09-30 06:01:57 +00:00 by kert · 0 comments
Owner

Severity: MEDIUM
Package: oauthlib @ 3.3.1
Fixed in: 4.0.0

Summary

A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.

Affected Component

  • File: oauthlib/oauth2/rfc6749/grant_types/authorization_code.py
  • Functions: code_challenge_method_plain, code_challenge_method_s256
  • Vulner

Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-49265

**Severity:** MEDIUM **Package:** `oauthlib` @ `3.3.1` **Fixed in:** `4.0.0` ## Summary A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation of the Authorization Code Grant flow. The `code_challenge_method_plain` function uses Python's standard `==` operator for string comparison instead of a constant-time comparison function, potentially allowing timing-based attacks. ## Affected Component - File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py` - Functions: `code_challenge_method_plain`, `code_challenge_method_s256` - Vulner **Reference:** https://nvd.nist.gov/vuln/detail/CVE-2026-49265
kert added this to the P21: Package Supply Chain — inventory, mirrors, drift, vuln scanning milestone 2026-09-30 06:01:57 +00:00
kert added the qualityci labels 2026-09-30 06:01:57 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: homelab/stack#891