[pkg-vuln] CVE-2026-49265 in oauthlib@3.3.1 #891
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Severity: MEDIUM
Package:
oauthlib@3.3.1Fixed in:
4.0.0Summary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The
code_challenge_method_plainfunctionuses Python's standard
==operator for string comparison instead of aconstant-time comparison function, potentially allowing timing-based attacks.
Affected Component
oauthlib/oauth2/rfc6749/grant_types/authorization_code.pycode_challenge_method_plain,code_challenge_method_s256Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-49265