oauthlib 4.0.0 was released on September 28, 2026 and fixes two advisories. Every published oauthlib 3.x release (through 3.3.1) is affected, and 4.0.0 is the first oauthlib release with the fixes:
databricks-sql-connector 4.6.0 (and main) requires oauthlib = "^3.1.0", i.e. >=3.1.0,<4.0.0, which prevents downstream consumers from resolving the fixes. Dependency scanners such as pip-audit flag every project that depends on the connector.
Both vulnerabilities are on the OAuth provider side, which the connector does not use, and 4.0.0 looks compatible with the connector's client-side usage:
src/databricks/sql/auth/oauth.py only uses WebApplicationClient (prepare_authorization_request, parse_request_uri_response, prepare_request_body, prepare_refresh_body) and OAuth2Error.
- The 4.0.0 breaking changes are provider-side (
RevocationEndpoint JSONP removal, grant-type validation order in the token grants) plus removal of the callback parameter from prepare_token_revocation_request, which the connector does not call.
- oauthlib 4.0.0 requires Python
>=3.9; the connector already requires ^3.10.
Requests:
- Widen the constraint to
oauthlib = ">=3.1.0,<5.0.0" to allow 4.x.
- Publish a new release to PyPI so downstream consumers can resolve both advisories.
oauthlib 4.0.0 was released on September 28, 2026 and fixes two advisories. Every published oauthlib 3.x release (through 3.3.1) is affected, and 4.0.0 is the first oauthlib release with the fixes:
==instead of a constant-time comparison; fixed in Improve PKCE code comparison oauthlib/oauthlib#963). Affects oauthlib>=3.0.0. The advisory lists 3.3.2 as patched, but no oauthlib 3.3.2 has been published; the fix shipped in 4.0.0.RevocationEndpoint(fixed in Remove JSONP support from token revocation oauthlib/oauthlib#951). Affects oauthlib>=0.6.1,<=3.3.1; patched in 4.0.0.databricks-sql-connector4.6.0 (andmain) requiresoauthlib = "^3.1.0", i.e.>=3.1.0,<4.0.0, which prevents downstream consumers from resolving the fixes. Dependency scanners such aspip-auditflag every project that depends on the connector.Both vulnerabilities are on the OAuth provider side, which the connector does not use, and 4.0.0 looks compatible with the connector's client-side usage:
src/databricks/sql/auth/oauth.pyonly usesWebApplicationClient(prepare_authorization_request,parse_request_uri_response,prepare_request_body,prepare_refresh_body) andOAuth2Error.RevocationEndpointJSONP removal, grant-type validation order in the token grants) plus removal of thecallbackparameter fromprepare_token_revocation_request, which the connector does not call.>=3.9; the connector already requires^3.10.Requests:
oauthlib = ">=3.1.0,<5.0.0"to allow 4.x.