Information Exposure Through Timing Discrepancy in oauthlib - CVE-2026-49265
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to obtain an access token and take over an account.
The vulnerability exists due to an observable timing discrepancy in the PKCE code verifier comparison functions when processing token endpoint requests. A remote attacker can send repeated requests and measure response times to obtain an access token and take over an account.
User interaction is required.