oauthlib
PyPI3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting oauthlibpage 1 of 1
- CVE-2022-36087MEDIUMCVSS 5.7EG 5.7fixed in 3.2.2 or 3.2.1, by version range2022-09-09
vulnerable: 3.1.1, 3.2.0
OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an attacker providing malicious redirect uri can cause denial of service. An attacker can also leverage usage of `uri…
- CVE-2026-49264MEDIUMCVSS 6.1EG 6.1fixed in 4.0.02026-09-29
vulnerable: 0.6.1 ... 3.3.1 (32 versions)
Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation ### Summary When `enable_jsonp=True`, oauthlib's `RevocationEndpoint` reflects the user-supplied `callback` parameter direct…
- CVE-2026-49265MEDIUMCVSS 6.8EG 6.8fixed in 4.0.02026-09-29
vulnerable: 3.0.0 ... 3.3.1 (10 versions)
Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208) ## Summary A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation of the Authorization Code Grant flow. The `code_challenge_metho…
Check whether oauthlib is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for oauthlib CVEs against the assets you own.
Book a Demo →