Skip to content

chore(deps): bump idna to 3.15 in seed poetry.lock files (CVE-2026-45409)#16003

Merged
davidkonigsberg merged 3 commits into
mainfrom
dependabot-alert-2074-devin
May 20, 2026
Merged

chore(deps): bump idna to 3.15 in seed poetry.lock files (CVE-2026-45409)#16003
davidkonigsberg merged 3 commits into
mainfrom
dependabot-alert-2074-devin

Conversation

@github-actions
Copy link
Copy Markdown
Contributor

@github-actions github-actions Bot commented May 20, 2026

Description

Refs Dependabot Alert #2074

Bumps idna to 3.15 across all seed poetry.lock files to address CVE-2026-45409 (GHSA-65pc-fj4g-8rjx). The vulnerability allows specially crafted inputs to idna.encode() to bypass the CVE-2024-3651 fix and cause denial-of-service via excessive resource consumption.

Changes Made

  • Bumped idna from 3.13 → 3.15 in seed/python-sdk/basic-auth-pw-omitted/poetry.lock
  • Bumped idna from 3.10 → 3.15 in seed/python-sdk/nullable/poetry.lock
  • Bumped idna from 3.10 → 3.15 in seed/python-sdk/mixed-file-directory/poetry.lock
  • Bumped idna from 3.10 → 3.15 in seed/python-sdk/file-upload/poetry.lock
  • Deleted scaffold file .github/dependabot-alerts/alert-2074.md

Testing

  • Verified all 190 poetry.lock files containing idna now have version 3.15
  • CI checks

Link to Devin session: https://app.devin.ai/sessions/6046e77a912f4424b7030a928177ab6d

@devin-ai-integration devin-ai-integration Bot changed the title [Dependabot Alert #2074] MEDIUM: idna vulnerability chore(deps): bump idna to 3.15 in seed poetry.lock files (CVE-2026-45409) May 20, 2026
@davidkonigsberg davidkonigsberg marked this pull request as ready for review May 20, 2026 10:25
Copy link
Copy Markdown

@claude claude Bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Claude Code Review

This repository is configured for manual code reviews. Comment @claude review to trigger a review and subscribe this PR to future pushes, or @claude review once for a one-time review.

Tip: disable this comment in your organization's Code Review settings.

@davidkonigsberg davidkonigsberg enabled auto-merge (squash) May 20, 2026 10:28
@davidkonigsberg davidkonigsberg merged commit b6af066 into main May 20, 2026
103 checks passed
@davidkonigsberg davidkonigsberg deleted the dependabot-alert-2074-devin branch May 20, 2026 10:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant