Skip to content

security: bump urllib3 to >=2.7.0#21

Merged
dantetemplar merged 1 commit into
mainfrom
security/urllib3-2.7.0
May 15, 2026
Merged

security: bump urllib3 to >=2.7.0#21
dantetemplar merged 1 commit into
mainfrom
security/urllib3-2.7.0

Conversation

@dantetemplar
Copy link
Copy Markdown
Member

Summary

  • Bump urllib3 to 2.7.0 (fixes decompression-bomb safeguard bypass in streaming API, CVE range >=2.6.0,<2.7.0)
  • Add durable minimum version constraint so future lock resolves cannot regress to vulnerable 2.6.x

Test plan

  • Lockfile resolves urllib3 2.7.0
  • CI passes

Made with Cursor

Mitigate decompression-bomb safeguard bypass in urllib3 2.6.x streaming API.
Add constraint so future lockfiles cannot regress below 2.7.0.

Co-authored-by: Cursor <cursoragent@cursor.com>
@dantetemplar dantetemplar merged commit 82857f0 into main May 15, 2026
5 of 7 checks passed
@dantetemplar dantetemplar deleted the security/urllib3-2.7.0 branch May 15, 2026 08:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant