MEDIUM 6.1 GitHub

CVE-2026-49264

Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation

### Summary When `enable_jsonp=True`, oauthlib's `RevocationEndpoint` reflects the user-supplied `callback` parameter directly into JavaScript response bodies on both success and error paths without validating that it is a legal JSONP callback name. This allows arbitrary JavaScript response generation instead of a restricted function call, making the documented JSONP revocation feature unsafe for browser-based JSONP consumption when attackers can influence `callback`. ### Details The issue is

Affected Products

References

Published: 2026-09-29 · Source: GitHub · Feed updated: 2026-09-30
This medium severity vulnerability with a CVSS score of 6.1 was published on 2026-09-29 via GitHub. Affected: pip/oauthlib >= 0.6.1, <= 3.3.1.
vulnfeed aggregates 10239 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.