Find a vulnerability
Search criteria
Related vulnerabilities
BREW-ANSIBLE-CVE-2026-49265 (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-09-30 18:44 – Updated: 2026-10-02 08:50 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": "bump",
"range_state": "fixed",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@4.0.0",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "ansible",
"purl": "pkg:brew/ansible"
},
"ranges": [
{
"events": [
{
"introduced": "2.8.4_1"
},
{
"fixed": "14.4.0_1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@4.0.0",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "4.0.0"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-ansible-CVE-2026-49265",
"modified": "2026-10-02T08:50:21Z",
"published": "2026-09-30T18:44:09Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-ANSIBLE@10-CVE-2026-49265 (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-09-30 19:48 – Updated: 2026-10-02 09:44 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": null,
"range_state": "affected",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@3.3.1",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "ansible@10",
"purl": "pkg:brew/ansible%4010"
},
"ranges": [
{
"events": [
{
"introduced": "10.6.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@3.3.1",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "3.3.1"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-ansible@10-CVE-2026-49265",
"modified": "2026-10-02T09:44:34Z",
"published": "2026-09-30T19:48:26Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-ANSIBLE@12-CVE-2026-49265 (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-09-30 18:43 – Updated: 2026-10-02 08:49 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": null,
"range_state": "affected",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@3.3.1",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "ansible@12",
"purl": "pkg:brew/ansible%4012"
},
"ranges": [
{
"events": [
{
"introduced": "12.2.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@3.3.1",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "3.3.1"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-ansible@12-CVE-2026-49265",
"modified": "2026-10-02T08:49:32Z",
"published": "2026-09-30T18:43:25Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-ANSIBLE@13-CVE-2026-49265 (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-09-30 21:01 – Updated: 2026-10-04 12:39 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": "bump",
"range_state": "fixed",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@4.0.0",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "ansible@13",
"purl": "pkg:brew/ansible%4013"
},
"ranges": [
{
"events": [
{
"introduced": "13.7.0"
},
{
"fixed": "13.8.0_3"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@4.0.0",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "4.0.0"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-ansible@13-CVE-2026-49265",
"modified": "2026-10-04T12:39:02Z",
"published": "2026-09-30T21:01:56Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-ANSIBLE@9-CVE-2026-49265 (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-09-30 18:43 – Updated: 2026-10-02 08:49 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": null,
"range_state": "affected",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@3.3.1",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "ansible@9",
"purl": "pkg:brew/ansible%409"
},
"ranges": [
{
"events": [
{
"introduced": "9.6.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@3.3.1",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "3.3.1"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-ansible@9-CVE-2026-49265",
"modified": "2026-10-02T08:49:40Z",
"published": "2026-09-30T18:43:46Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-AZURE-CLI-CVE-2026-49265 (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-09-30 21:04 – Updated: 2026-10-02 10:47 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": null,
"range_state": "affected",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@3.2.2",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "azure-cli",
"purl": "pkg:brew/azure-cli"
},
"ranges": [
{
"events": [
{
"introduced": "2.0.56"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@3.2.2",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "3.2.2"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-azure-cli-CVE-2026-49265",
"modified": "2026-10-02T10:47:17Z",
"published": "2026-09-30T21:04:28Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-CHARMCRAFT-CVE-2026-49265 (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-09-30 20:47 – Updated: 2026-10-02 10:41 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": "bump",
"range_state": "fixed",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@4.0.0",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "charmcraft",
"purl": "pkg:brew/charmcraft"
},
"ranges": [
{
"events": [
{
"introduced": "3.0.0"
},
{
"fixed": "4.4.2_1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@4.0.0",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "4.0.0"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-charmcraft-CVE-2026-49265",
"modified": "2026-10-02T10:41:44Z",
"published": "2026-09-30T20:47:24Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-CONFLUENCE-MARKDOWN… (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-09-30 21:05 – Updated: 2026-10-04 12:42 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": "bump",
"range_state": "fixed",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@4.0.0",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "confluence-markdown-exporter",
"purl": "pkg:brew/confluence-markdown-exporter"
},
"ranges": [
{
"events": [
{
"introduced": "5.4.0"
},
{
"fixed": "5.5.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@4.0.0",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "4.0.0"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-confluence-markdown-exporter-CVE-2026-49265",
"modified": "2026-10-04T12:42:37Z",
"published": "2026-09-30T21:05:37Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-DSTACK-CVE-2026-49265 (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-09-30 19:10 – Updated: 2026-10-02 09:13 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": "bump",
"range_state": "fixed",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@4.0.0",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "dstack",
"purl": "pkg:brew/dstack"
},
"ranges": [
{
"events": [
{
"introduced": "0.9.1"
},
{
"fixed": "0.22.1_1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@4.0.0",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "4.0.0"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-dstack-CVE-2026-49265",
"modified": "2026-10-02T09:13:40Z",
"published": "2026-09-30T19:10:36Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-DUPLICITY-CVE-2026-49265 (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-09-30 18:43 – Updated: 2026-10-02 08:50 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": "bump",
"range_state": "fixed",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@4.0.0",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "duplicity",
"purl": "pkg:brew/duplicity"
},
"ranges": [
{
"events": [
{
"introduced": "0.8.05_1"
},
{
"fixed": "3.2.1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@4.0.0",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "4.0.0"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-duplicity-CVE-2026-49265",
"modified": "2026-10-02T08:50:42Z",
"published": "2026-09-30T18:43:15Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-DVC-CVE-2026-49265 (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-10-04 22:06 – Updated: 2026-10-04 22:06 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": "bump",
"range_state": "fixed",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@4.0.0",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "dvc",
"purl": "pkg:brew/dvc"
},
"ranges": [
{
"events": [
{
"introduced": "2.0.10"
},
{
"fixed": "3.67.1_16"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@4.0.0",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "4.0.0"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-dvc-CVE-2026-49265",
"modified": "2026-10-04T22:06:36Z",
"published": "2026-10-04T22:06:36Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-EVERNOTE-BACKUP-CVE… (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-09-30 18:49 – Updated: 2026-10-02 08:51 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": "bump",
"range_state": "fixed",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@4.0.0",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "evernote-backup",
"purl": "pkg:brew/evernote-backup"
},
"ranges": [
{
"events": [
{
"introduced": "1.9.0"
},
{
"fixed": "1.14.0_2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@4.0.0",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "4.0.0"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-evernote-backup-CVE-2026-49265",
"modified": "2026-10-02T08:51:08Z",
"published": "2026-09-30T18:49:41Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-GCALCLI-CVE-2026-49265 (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-09-30 20:05 – Updated: 2026-10-02 10:00 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": "bump",
"range_state": "fixed",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@4.0.0",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "gcalcli",
"purl": "pkg:brew/gcalcli"
},
"ranges": [
{
"events": [
{
"introduced": "4.4.0"
},
{
"fixed": "4.5.1_14"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@4.0.0",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "4.0.0"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-gcalcli-CVE-2026-49265",
"modified": "2026-10-02T10:00:23Z",
"published": "2026-09-30T20:05:34Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-GGSHIELD-CVE-2026-49265 (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-09-30 20:53 – Updated: 2026-10-02 10:47 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": null,
"range_state": "affected",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@3.3.1",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "ggshield",
"purl": "pkg:brew/ggshield"
},
"ranges": [
{
"events": [
{
"introduced": "1.19.1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@3.3.1",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "3.3.1"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-ggshield-CVE-2026-49265",
"modified": "2026-10-02T10:47:17Z",
"published": "2026-09-30T20:53:31Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-GYB-CVE-2026-49265 (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-09-30 20:50 – Updated: 2026-10-02 10:33 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": "bump",
"range_state": "fixed",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@4.0.0",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "gyb",
"purl": "pkg:brew/gyb"
},
"ranges": [
{
"events": [
{
"introduced": "1.73"
},
{
"fixed": "1.97"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@4.0.0",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "4.0.0"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-gyb-CVE-2026-49265",
"modified": "2026-10-02T10:33:36Z",
"published": "2026-09-30T20:50:54Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-HERMES-AGENT-CVE-20… (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-10-04 11:46 – Updated: 2026-10-04 11:46 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": "bump",
"range_state": "fixed",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@4.0.0",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "hermes-agent",
"purl": "pkg:brew/hermes-agent"
},
"ranges": [
{
"events": [
{
"introduced": "2026.9.14"
},
{
"fixed": "2026.9.21_2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@4.0.0",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "4.0.0"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-hermes-agent-CVE-2026-49265",
"modified": "2026-10-04T11:46:49Z",
"published": "2026-10-04T11:46:49Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-MCP-ATLASSIAN-CVE-2… (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-09-30 20:03 – Updated: 2026-10-02 10:02 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": "bump",
"range_state": "fixed",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@4.0.0",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "mcp-atlassian",
"purl": "pkg:brew/mcp-atlassian"
},
"ranges": [
{
"events": [
{
"introduced": "0.11.9"
},
{
"fixed": "0.23.1_1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@4.0.0",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "4.0.0"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-mcp-atlassian-CVE-2026-49265",
"modified": "2026-10-02T10:02:28Z",
"published": "2026-09-30T20:03:26Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-MCP-GOOGLE-SHEETS-C… (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-09-30 18:52 – Updated: 2026-10-02 08:57 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": "bump",
"range_state": "fixed",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@4.0.0",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "mcp-google-sheets",
"purl": "pkg:brew/mcp-google-sheets"
},
"ranges": [
{
"events": [
{
"introduced": "0.5.1"
},
{
"fixed": "0.6.3_5"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@4.0.0",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "4.0.0"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-mcp-google-sheets-CVE-2026-49265",
"modified": "2026-10-02T08:57:19Z",
"published": "2026-09-30T18:52:07Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-PARSEDMARC-CVE-2026-49265 (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-09-30 20:46 – Updated: 2026-10-02 10:30 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": "bump",
"range_state": "fixed",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@4.0.0",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "parsedmarc",
"purl": "pkg:brew/parsedmarc"
},
"ranges": [
{
"events": [
{
"introduced": "8.11.0"
},
{
"fixed": "11.0.3_1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@4.0.0",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "4.0.0"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-parsedmarc-CVE-2026-49265",
"modified": "2026-10-02T10:30:40Z",
"published": "2026-09-30T20:46:41Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-PROWLER-CVE-2026-49265 (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-09-30 20:14 – Updated: 2026-10-02 10:10 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": "bump",
"range_state": "fixed",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@4.0.0",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "prowler",
"purl": "pkg:brew/prowler"
},
"ranges": [
{
"events": [
{
"introduced": "3.0.1"
},
{
"fixed": "5.43.0_2"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@4.0.0",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "4.0.0"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-prowler-CVE-2026-49265",
"modified": "2026-10-02T10:10:09Z",
"published": "2026-09-30T20:14:52Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-ROCKCRAFT-CVE-2026-49265 (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-09-30 18:56 – Updated: 2026-10-02 09:01 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": "bump",
"range_state": "fixed",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@4.0.0",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "rockcraft",
"purl": "pkg:brew/rockcraft"
},
"ranges": [
{
"events": [
{
"introduced": "1.16.0"
},
{
"fixed": "1.20.0_1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@4.0.0",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "4.0.0"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-rockcraft-CVE-2026-49265",
"modified": "2026-10-02T09:01:04Z",
"published": "2026-09-30T18:56:30Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-SCOUTSUITE-CVE-2026-49265 (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-09-30 20:42 – Updated: 2026-10-02 10:44 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": "bump",
"range_state": "fixed",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@4.0.0",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "scoutsuite",
"purl": "pkg:brew/scoutsuite"
},
"ranges": [
{
"events": [
{
"introduced": "5.13.0"
},
{
"fixed": "5.14.0_17"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@4.0.0",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "4.0.0"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-scoutsuite-CVE-2026-49265",
"modified": "2026-10-02T10:44:02Z",
"published": "2026-09-30T20:42:56Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-SICKCHILL-CVE-2026-49265 (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-09-30 19:29 – Updated: 2026-10-02 09:24 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": "bump",
"range_state": "fixed",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@4.0.0",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "sickchill",
"purl": "pkg:brew/sickchill"
},
"ranges": [
{
"events": [
{
"introduced": "2023.5.30"
},
{
"fixed": "2024.3.1_9"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@4.0.0",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "4.0.0"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-sickchill-CVE-2026-49265",
"modified": "2026-10-02T09:24:44Z",
"published": "2026-09-30T19:29:04Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-SNAPCRAFT-CVE-2026-49265 (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-09-30 21:12 – Updated: 2026-10-02 10:54 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": "bump",
"range_state": "fixed",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@4.0.0",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "snapcraft",
"purl": "pkg:brew/snapcraft"
},
"ranges": [
{
"events": [
{
"introduced": "3.9"
},
{
"fixed": "9.1.3_1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@4.0.0",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "4.0.0"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-snapcraft-CVE-2026-49265",
"modified": "2026-10-02T10:54:23Z",
"published": "2026-09-30T21:12:52Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-TWARC-CVE-2026-49265 (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-10-04 21:48 – Updated: 2026-10-04 21:48 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": "bump",
"range_state": "fixed",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@4.0.0",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "twarc",
"purl": "pkg:brew/twarc"
},
"ranges": [
{
"events": [
{
"introduced": "1.8.5"
},
{
"fixed": "2.14.1_5"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@4.0.0",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "4.0.0"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-twarc-CVE-2026-49265",
"modified": "2026-10-04T21:48:39Z",
"published": "2026-10-04T21:48:39Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
BREW-VDIRSYNCER-CVE-2026-49265 (GHSA-XPV3-W29H-X7CV)
Vulnerability from osv_homebrew – Published: 2026-09-30 21:43 – Updated: 2026-10-02 21:08 – Source websiteSummary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"ecosystem_specific": {
"fix": "bump",
"range_state": "fixed",
"resource": "oauthlib",
"resource_purl": "pkg:pypi/oauthlib@4.0.0",
"upstream_fixed_in": "4.0.0"
},
"package": {
"ecosystem": "Homebrew",
"name": "vdirsyncer",
"purl": "pkg:brew/vdirsyncer"
},
"ranges": [
{
"events": [
{
"introduced": "0.16.7"
},
{
"fixed": "0.21.0_1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"database_specific": {
"confidence": "high",
"source": "matched",
"strategy": "registry",
"upstream_evidence": [
{
"ecosystem": "PyPI",
"key": "pkg:pypi/oauthlib@4.0.0",
"name": "oauthlib",
"resource": "oauthlib",
"strategy": "registry",
"subject_version": "4.0.0"
}
]
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "BREW-vdirsyncer-CVE-2026-49265",
"modified": "2026-10-02T21:08:48Z",
"published": "2026-09-30T21:43:26Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.7.3",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)",
"upstream": [
"GHSA-xpv3-w29h-x7cv",
"CVE-2026-49265",
"PYSEC-2026-4114"
]
}
GHSA-XPV3-W29H-X7CV
Vulnerability from github – Published: 2026-09-29 17:56 – Updated: 2026-09-29 17:56Summary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
{
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "oauthlib"
},
"ranges": [
{
"events": [
{
"introduced": "3.0.0"
},
{
"fixed": "4.0.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-49265"
],
"database_specific": {
"cwe_ids": [
"CWE-208"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-29T17:56:31Z",
"nvd_published_at": null,
"severity": "MODERATE"
},
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "GHSA-xpv3-w29h-x7cv",
"modified": "2026-09-29T17:56:31Z",
"published": "2026-09-29T17:56:31Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)"
}
PYSEC-2026-4114
Vulnerability from pysec - Published: 2026-10-01 16:38 - Updated: 2026-10-01 17:10Summary
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
Affected Component
- File:
oauthlib/oauth2/rfc6749/grant_types/authorization_code.py - Functions:
code_challenge_method_plain,code_challenge_method_s256 - Vulnerability Type: CWE-208 (Observable Timing Discrepancy)
Technical Details
Python's == operator uses short-circuit evaluation when comparing strings:
1. Returns False immediately if lengths differ
2. Compares characters left-to-right, stopping at first mismatch
This means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Proof of Concept
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) |
Fast reject | 0.34106s |
49 chars correct (A*49 + B) |
Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
Attack Scenario
- Attacker intercepts
authorization_codevia Custom URI Scheme Hijacking - PKCE blocks token request — attacker lacks
code_verifier - Attacker sends repeated requests to
/tokenendpoint measuring response times - Using timing oracle, attacker recovers
code_verifiercharacter by character - Attacker obtains Access Token → Account Takeover
Note: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Recommended Fix
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
| Name | purl | oauthlib | pkg:pypi/oauthlib |
|---|
{
"affected": [
{
"package": {
"ecosystem": "PyPI",
"name": "oauthlib",
"purl": "pkg:pypi/oauthlib"
},
"ranges": [
{
"events": [
{
"introduced": "3.0.0"
},
{
"fixed": "4.0.0"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"3.0.0",
"3.0.1",
"3.0.2",
"3.1.0",
"3.1.1",
"3.2.0",
"3.2.1",
"3.2.2",
"3.3.0",
"3.3.1"
]
}
],
"aliases": [
"CVE-2026-49265",
"GHSA-xpv3-w29h-x7cv"
],
"details": "## Summary\n\nA timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation \nof the Authorization Code Grant flow. The `code_challenge_method_plain` function \nuses Python\u0027s standard `==` operator for string comparison instead of a \nconstant-time comparison function, potentially allowing timing-based attacks.\n\n## Affected Component\n\n- File: `oauthlib/oauth2/rfc6749/grant_types/authorization_code.py`\n- Functions: `code_challenge_method_plain`, `code_challenge_method_s256`\n- Vulnerability Type: CWE-208 (Observable Timing Discrepancy)\n\n## Technical Details\n\nPython\u0027s `==` operator uses short-circuit evaluation when comparing strings:\n1. Returns `False` immediately if lengths differ\n2. Compares characters left-to-right, stopping at first mismatch\n\nThis means comparison time varies linearly with the length of the common prefix \nbetween the attacker-supplied verifier and the stored challenge, creating a \nmeasurable timing oracle.\n\n## Proof of Concept\n\nTested locally against oauthlib source (network jitter eliminated to isolate \npure Python execution time):\n\n| Input | Result | Time (10M iterations) |\n|---|---|---|\n| Wrong first char (`B` + `A`*49) | Fast reject | 0.34106s |\n| 49 chars correct (`A`*49 + `B`) | Deep compare | 0.37847s |\n| **Difference** | | **0.03741s** |\n\nThe ~37ms delta over 10M iterations corresponds to nanosecond-level differences \nper call, which are statistically exploitable under controlled conditions.\n\n## Attack Scenario\n\n1. Attacker intercepts `authorization_code` via Custom URI Scheme Hijacking\n2. PKCE blocks token request \u2014 attacker lacks `code_verifier`\n3. Attacker sends repeated requests to `/token` endpoint measuring response times\n4. Using timing oracle, attacker recovers `code_verifier` character by character\n5. Attacker obtains Access Token \u2192 Account Takeover\n\n\u003e **Note:** Practical exploitability is limited due to the single-use nature of \n\u003e authorization codes and real-world network noise. However, the vulnerable \n\u003e pattern should be corrected as a defense-in-depth measure.\n\n## Recommended Fix\n\nReplace `==` with `hmac.compare_digest()` for constant-time comparison:\n\ncr: Elvin Latifli",
"id": "PYSEC-2026-4114",
"modified": "2026-10-01T17:10:33.763932Z",
"published": "2026-10-01T16:38:40.027560Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/security/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/pull/963"
},
{
"type": "WEB",
"url": "https://github.com/oauthlib/oauthlib/commit/40b0ab56da3682c2484a4b78bbff309f8025d950"
},
{
"type": "PACKAGE",
"url": "https://github.com/oauthlib/oauthlib"
},
{
"type": "PACKAGE",
"url": "https://pypi.org/project/oauthlib"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-xpv3-w29h-x7cv"
},
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-49265"
}
],
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
"type": "CVSS_V3"
}
],
"summary": "Oauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)"
}