Skip to content

Vulnerabilities to resolve #2135

@Didayolo

Description

@Didayolo
  • pyasn1 has a DoS vulnerability in decoder (GHSA-63vm-454h-vhhq)
    Recommandation: Add a limit to the allowed bytes in the decoder.

  • Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API) (GHSA-38jv-5279-wg99)
    Remediation: Upgrade to at least urllib3 v2.6.3 in which the library does not decode content of redirect responses when preload_content=False.
    Fix: Bump urllib3 from 2.5.0 to 2.6.3 in /tests #2120

Metadata

Metadata

Assignees

No one assigned

    Labels

    Post-itInternal ideas

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions