Hi team,
Our application uses Databricks SQL Connector, and our security checks report two vulnerabilities in its oauthlib dependency:
CVE-2026-49264: JSONP callback injection.
CVE-2026-49265: PKCE timing attack.
Both are fixed in oauthlib 4.0.0. We currently use connector 4.4.0, but upgrading to the latest published version, 4.6.0, would not resolve this because both require oauthlib>=3.1.0,<4.0.0.
We see that PR #971 was merged on October 6 to allow oauthlib 4.x. Thank you for addressing this.
Could you please confirm when a release containing this change will be published to PyPI? Is a patch release possible? Our CI security checks are currently blocking our application build and release.
Thank you.
Hi team,
Our application uses Databricks SQL Connector, and our security checks report two vulnerabilities in its oauthlib dependency:
CVE-2026-49264: JSONP callback injection.
CVE-2026-49265: PKCE timing attack.
Both are fixed in oauthlib 4.0.0. We currently use connector 4.4.0, but upgrading to the latest published version, 4.6.0, would not resolve this because both require oauthlib>=3.1.0,<4.0.0.
We see that PR #971 was merged on October 6 to allow oauthlib 4.x. Thank you for addressing this.
Could you please confirm when a release containing this change will be published to PyPI? Is a patch release possible? Our CI security checks are currently blocking our application build and release.
Thank you.