CVE-2026-49265Medium· 6.8▾ SunlitOauthlib: Timing Attack Vulnerability in PKCE code_verifier Comparison (CWE-208)
▾ Sunlit zone — Low / medium · no exploitation signal
impact 37.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A timing side-channel vulnerability exists in the PKCE (RFC 7636) implementation
of the Authorization Code Grant flow. The code_challenge_method_plain function
uses Python's standard == operator for string comparison instead of a
constant-time comparison function, potentially allowing timing-based attacks.
oauthlib/oauth2/rfc6749/grant_types/authorization_code.pycode_challenge_method_plain, code_challenge_method_s256Python's == operator uses short-circuit evaluation when comparing strings:
False immediately if lengths differThis means comparison time varies linearly with the length of the common prefix between the attacker-supplied verifier and the stored challenge, creating a measurable timing oracle.
Tested locally against oauthlib source (network jitter eliminated to isolate pure Python execution time):
| Input | Result | Time (10M iterations) |
|---|---|---|
Wrong first char (B + A*49) | Fast reject | 0.34106s |
49 chars correct (A*49 + B) | Deep compare | 0.37847s |
| Difference | 0.03741s |
The ~37ms delta over 10M iterations corresponds to nanosecond-level differences per call, which are statistically exploitable under controlled conditions.
authorization_code via Custom URI Scheme Hijackingcode_verifier/token endpoint measuring response timescode_verifier character by characterNote: Practical exploitability is limited due to the single-use nature of authorization codes and real-world network noise. However, the vulnerable pattern should be corrected as a defense-in-depth measure.
Replace == with hmac.compare_digest() for constant-time comparison:
cr: Elvin Latifli
oauthlib >= 3.0.0, < 4.0.0Upgrade to a patched release:
oauthlib 4.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-49264Medium· 6.1Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation
CVE-2026-85725Medium· 5.9LightRAG provides simple and fast retrieval-augmented generation
CVE-2026-69247Medium· 5.9cryptography is a package designed to expose cryptographic primitives and recipes to Python developers
CVE-2026-59218Medium· 5.3Open WebUI: Account enumeration via observable login timing discrepancy
CVE-2025-59425High· 7.5vllm: Timing Attack in vLLM API Token Verification Leading to Authentication Bypass (CVE-2025-59425)
CVE-2026-77696Low· 3.7Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel. Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secre…