deps: pin oauthlib>=4.0.0 (CVE-2026-49264, CVE-2026-49265) - #2721
friedrichwilken wants to merge 1 commit into
Conversation
|
Adding the "do-not-merge/release-note-label-needed" label because no release-note block was detected, please follow our release note process to remove it. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
Welcome @friedrichwilken! |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: friedrichwilken The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
Fixes #2720.
Two CVEs affect
oauthlib3.x:code_verifiercomparison (CWE-208)RevocationEndpointThe chain is
kubernetes → requests-oauthlib → oauthlib>=3.0.0. Sincerequests-oauthlibonly requires>=3.0.0, resolvers can land on the vulnerable 3.x line without a tighter constraint here.The upstream fix is requests/requests-oauthlib#577 (bump their own lower bound to
>=4.0.0), but that project is slow-moving. This PR adds the same protective direct pin used in #2016, following the same pattern that #2434 later cleaned up once the underlying issue was resolved.The pin can be removed once
requests-oauthlibships a release withoauthlib>=4.0.0in its own requirements.