MEDIUM 6.1 GitHub
CVE-2026-49264
Oauthlib : Unsafe JSONP callback injection in RevocationEndpoint allows arbitrary JavaScript response generation
### Summary
When `enable_jsonp=True`, oauthlib's `RevocationEndpoint` reflects the user-supplied `callback` parameter directly into JavaScript response bodies on both success and error paths without validating that it is a legal JSONP callback name. This allows arbitrary JavaScript response generation instead of a restricted function call, making the documented JSONP revocation feature unsafe for browser-based JSONP consumption when attackers can influence `callback`.
### Details
The issue is
Affected Products
- pip/oauthlib >= 0.6.1, <= 3.3.1
References
- https://github.com/advisories/GHSA-hj66-6f7g-4r5v
- https://github.com/oauthlib/oauthlib/security/advisories/GHSA-hj66-6f7g-4r5v
- https://github.com/oauthlib/oauthlib/pull/951
- https://github.com/oauthlib/oauthlib/commit/c888359f3c42bec235b2c5caab2069c9ed62457c
This medium severity vulnerability with a CVSS score of 6.1 was published on 2026-09-29 via GitHub. Affected: pip/oauthlib >= 0.6.1, <= 3.3.1.
vulnfeed aggregates 10239 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.