Skip to content

security: bump urllib3 from 2.6.2 to 2.6.3#220

Closed
hemna wants to merge 1 commit intomasterfrom
fix/urllib3-security
Closed

security: bump urllib3 from 2.6.2 to 2.6.3#220
hemna wants to merge 1 commit intomasterfrom
fix/urllib3-security

Conversation

@hemna
Copy link
Copy Markdown
Collaborator

@hemna hemna commented Mar 24, 2026

Summary

  • Bumps urllib3 from 2.6.2 to 2.6.3
  • Fixes CVE-2026-21441 (8.9 High severity) - decompression-bomb safeguards of the streaming API were bypassed when HTTP redirects were followed

Closes #210

Fixes CVE-2026-21441 (8.9 High severity) - decompression-bomb safeguards
of the streaming API were bypassed when HTTP redirects were followed.

Closes #210
@hemna hemna force-pushed the fix/urllib3-security branch from b9c5c93 to dc9fb92 Compare March 24, 2026 17:39
@hemna
Copy link
Copy Markdown
Collaborator Author

hemna commented Mar 24, 2026

Closing to rename branch - CI has a bug with / in branch names

@hemna hemna closed this Mar 24, 2026
@hemna hemna deleted the fix/urllib3-security branch March 24, 2026 17:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant