Information Exposure Through Timing Discrepancy in oauthlib - CVE-2026-49265

 

Information Exposure Through Timing Discrepancy in oauthlib - CVE-2026-49265

Published: September 28, 2026


Vulnerability identifier: #VU152413
CSH Severity: Medium
CVSS v4: 7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-49265
CWE-ID: CWE-208
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain an access token and take over an account.

The vulnerability exists due to an observable timing discrepancy in the PKCE code verifier comparison functions when processing token endpoint requests. A remote attacker can send repeated requests and measure response times to obtain an access token and take over an account.

User interaction is required.


Affected software

oauthlib

How to mitigate CVE-2026-49265

Install security update from vendor's website.

oauthlib - update to 3.3.2

External References

Related Security Bulletins