Skip to content

fix: bump urllib3 to 2.8.0 to resolve CVE-2026-97687 and CVE-2026-97689 - #245

Merged
jeff-schnitter merged 2 commits into
mainfrom
bump-urllib3-2.8.0
Oct 2, 2026
Merged

jeff-schnitter merged 2 commits into
mainfrom
bump-urllib3-2.8.0

Conversation

@jeff-schnitter

Copy link
Copy Markdown
Collaborator

Summary

  • Bumps urllib3 from >= 2.7.0 to >= 2.8.0 to fix two HIGH severity CVEs found by Trivy in the Docker image scan
  • CVE-2026-97687 — HTTPS proxy TLS configuration override (traffic interception)
  • CVE-2026-97689 — DoS via unbounded memory allocation in chunk parser

Test plan

  • CI green
  • Docker Trivy scan passes

🤖 Generated with Claude Code

jeff-schnitter and others added 2 commits October 1, 2026 16:06
@jeff-schnitter
jeff-schnitter merged commit e85557c into main Oct 2, 2026
6 of 7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant