Repository navigation
deps: pin oauthlib>=4.0.0 (CVE-2026-49264, CVE-2026-49265) - #2721
kubernetes-prow[bot] merged 1 commit into
Conversation
|
Welcome @friedrichwilken! |
|
/lgtm |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: friedrichwilken, yliaog The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
d680073
into
kubernetes-client:master
Fixes #2720.
Two CVEs affect
oauthlib3.x:code_verifiercomparison (CWE-208)RevocationEndpointThe chain is
kubernetes → requests-oauthlib → oauthlib>=3.0.0. Sincerequests-oauthlibonly requires>=3.0.0, resolvers can land on the vulnerable 3.x line without a tighter constraint here.The upstream fix is requests/requests-oauthlib#577 (bump their own lower bound to
>=4.0.0), but that project is slow-moving. This PR adds the same protective direct pin used in #2016, following the same pattern that #2434 later cleaned up once the underlying issue was resolved.The pin can be removed once
requests-oauthlibships a release withoauthlib>=4.0.0in its own requirements.