PT-2026-102981 · Pypi · Oauthlib

CVE-2026-49265

·

Published

2026-09-29

·

Updated

2026-10-01

CVSS v3.1

6.8

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions oauthlib (affected versions not specified)
Description A timing side-channel exists in the PKCE implementation of the Authorization Code Grant flow. The functions code challenge method plain() and code challenge method s256() in the file oauthlib/oauth2/rfc6749/grant types/authorization code.py use the standard == operator for string comparison. This operator employs short-circuit evaluation, returning False immediately if lengths differ or stopping at the first character mismatch. This creates a timing oracle where the response time varies based on the length of the common prefix between the supplied verifier and the stored challenge. An attacker who intercepts an authorization code could potentially use the /token endpoint to recover the code verifier character by character to obtain an access token.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the /token endpoint to minimize the risk of exploitation.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49265
GHSA-XPV3-W29H-X7CV
PYSEC-2026-4114

Affected Products

Oauthlib