Back

MEDIUM

OAuthLib vulnerable DoS when attacker provides malicious IPV6 URI

Published Sep 9, 2022

Description

OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an attacker providing malicious redirect uri can cause denial of service. An attacker can also leverage usage of `uri_validate` functions depending where it is used. OAuthLib applications using OAuth2.0 provider support or use directly `uri_validate` are affected by this issue. Version 3.2.1 contains a patch. There are no known workarounds.

Affected products

Remediation

Red Hat mitigation

The redirect_uri can be verified in the web toolkit before OAuthLib is called. Check to see if `:` is present to reject the request can prevent the denial of service, assuming no port or IPv6 is fundamentally required.

Metrics

References (19)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 9, 2022
Updated Apr 22, 2025
Reserved Jul 15, 2022
CISA Vulnrichment
Updated Apr 22, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 9, 2022
GHSA-3PGJ-PG6C-R5P7