Skip to content

fix: bump urllib3 to >=2.7.0 (CVE-2026-44432, CVE-2026-44431) - #6103

Open
mfleader wants to merge 1 commit into
ogx-ai:release-0.4.xfrom
mfleader:fix/CVE-2026-44432-urllib3
Open

fix: bump urllib3 to >=2.7.0 (CVE-2026-44432, CVE-2026-44431)#6103
mfleader wants to merge 1 commit into
ogx-ai:release-0.4.xfrom
mfleader:fix/CVE-2026-44432-urllib3

Conversation

@mfleader

Copy link
Copy Markdown
Contributor

What does this PR do?

Bump urllib3 to >=2.7.0 to address two CVEs:

GHSA-mf9v-mfxr-j63j
GHSA-qccp-gfcp-xxvc

Only applies to release-0.4.x; urllib3 already >=2.7.0 on main.

Test Plan

No functional changes. Version floor pin only.

Comment thread uv.lock Outdated
@mfleader
mfleader force-pushed the fix/CVE-2026-44432-urllib3 branch 2 times, most recently from 997e712 to ba60b34 Compare June 16, 2026 20:22

@cdoern cdoern left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

uv.lock still needs the change of urllib

@skamenan7
skamenan7 self-requested a review June 16, 2026 20:26
Signed-off-by: Matthew F Leader <mleader@redhat.com>
@mfleader
mfleader force-pushed the fix/CVE-2026-44432-urllib3 branch from ba60b34 to e832bdd Compare June 16, 2026 20:36
@mfleader
mfleader requested a review from cdoern June 16, 2026 20:39
@leseb

leseb commented Jul 7, 2026

Copy link
Copy Markdown
Member

@mfleader what's the status here?

@mfleader

mfleader commented Jul 7, 2026

Copy link
Copy Markdown
Contributor Author

@leseb I made the changes to uv.lock that @cdoern. It's waiting on re-review (and then approval and merge)

@mergify

mergify Bot commented Jul 27, 2026

Copy link
Copy Markdown
Contributor

This pull request has merge conflicts that must be resolved before it can be merged. @mfleader please rebase it. https://docs.github.com/en/pull-requests/collaborating-with-pull-requests/working-with-forks/syncing-a-fork

@mergify mergify Bot added the needs-rebase label Jul 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants