Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade oauthlib to version 4.0.0 or higher.
Affected versions of this package are vulnerable to Timing Attack via the code_challenge_method_s256 and code_challenge_method_plain functions in oauthlib/oauth2/rfc6749/grant_types/authorization_code.py, which compare PKCE code verifiers and challenges using the non-constant-time == operator. An attacker can exploit the resulting timing side-channel to progressively recover a valid PKCE code verifier or challenge through repeated token-endpoint requests, ultimately bypassing the PKCE authorization code binding and gaining unauthorized access to protected resources.