Skip to content

Release ETA for the oauthlib 4.0.0 dependency fix #980

Description

@rupeshkumar-aa

Hi team,

Our application uses Databricks SQL Connector, and our security checks report two vulnerabilities in its oauthlib dependency:

CVE-2026-49264: JSONP callback injection.
CVE-2026-49265: PKCE timing attack.
Both are fixed in oauthlib 4.0.0. We currently use connector 4.4.0, but upgrading to the latest published version, 4.6.0, would not resolve this because both require oauthlib>=3.1.0,<4.0.0.

We see that PR #971 was merged on October 6 to allow oauthlib 4.x. Thank you for addressing this.

Could you please confirm when a release containing this change will be published to PyPI? Is a patch release possible? Our CI security checks are currently blocking our application build and release.

Thank you.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions