Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Security: pin oauthlib>=4.0.0 (CVE-2026-49264, CVE-2026-49265)

Aperta
#2,720 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 3 giorni

@friedrichwilken ci sta già lavorando.

Dal 1/10/2026.

  • #2721 di @friedrichwilken — aperta

Valutazione

Difficoltà
1/5
Tempo stimato
Meno di un'ora
Idoneità per principianti
30/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
python
Ambito
security

Direzione di ricerca

Start with requirements.txt and compare the requested dependency pin with the protective pattern from #2016. Add the direct oauthlib>=4.0.0 constraint, then verify that the dependency resolves to the fixed 4.0.0 line; the issue notes that this pin can later be removed after requests-oauthlib ships its raised lower bound.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Two CVEs were published against oauthlib affecting all 3.x releases:

  • CVE-2026-49265 -- Timing attack vulnerability in PKCE code_verifier comparison (CWE-208)
  • CVE-2026-49264 -- Unsafe JSONP callback injection in RevocationEndpoint

Both are fixed in oauthlib 4.0.0.

The dependency chain here is:

kubernetes → requests-oauthlib → oauthlib>=3.0.0

requests-oauthlib declares oauthlib>=3.0.0, which allows resolvers to land on the vulnerable 3.x line. The upstream fix is requests/requests-oauthlib#577, but that project is slow-moving.

The same protective pattern was used before in #2016 -- adding a direct oauthlib pin to requirements.txt. A PR with the one-line fix is attached.

Once requests/requests-oauthlib#577 merges and a new requests-oauthlib release ships with the raised lower bound, this pin can be removed (same as #2434 cleaned up the previous one).

Lingua principale
Python
Stelle
7.7k
Fork
3.5k
Merge medio
3g 4h
PR unite (30g)
9

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di kubernetes-client/python

Tutte le issue di kubernetes-client/python

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.