Skip to content

chore(deps)(deps): bump the python-minor-patch group across 1 directory with 12 updates - #1013

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-minor-patch-8477e74f95
Open

chore(deps)(deps): bump the python-minor-patch group across 1 directory with 12 updates#1013
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-minor-patch-8477e74f95

chore(deps)(deps): bump the python-minor-patch group across 1 directo…

1307ea6
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / Trivy failed Aug 17, 2026 in 3s

25 new alerts including 13 high severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 13 high
  • 7 medium
  • 5 low

Alerts not introduced by this pull request might have been detected because the code changes were too large.

See annotations below for details.

View all branch alerts.

Annotations

Check failure on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

MCP Python SDK: WebSocket server transport does not support Host/Origin validation High

Package: mcp
Installed Version: 1.27.1
Vulnerability CVE-2026-59950
Severity: HIGH
Fixed Version: 1.28.1
Link: CVE-2026-59950

Check failure on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks High

Package: mcp
Installed Version: 1.27.1
Vulnerability CVE-2026-52870
Severity: HIGH
Fixed Version: 1.27.2
Link: CVE-2026-52870

Check failure on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal High

Package: mcp
Installed Version: 1.27.1
Vulnerability CVE-2026-52869
Severity: HIGH
Fixed Version: 1.27.2
Link: CVE-2026-52869

Check failure on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings High

Package: soupsieve
Installed Version: 2.8.3
Vulnerability CVE-2026-49477
Severity: HIGH
Fixed Version: 2.8.4
Link: CVE-2026-49477

Check failure on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

python-soupsieve: Soupsieve: Denial of Service via crafted CSS selector string High

Package: soupsieve
Installed Version: 2.8.3
Vulnerability CVE-2026-49476
Severity: HIGH
Fixed Version: 2.8.4
Link: CVE-2026-49476

Check failure on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

joserfc is a Python library that provides an implementation of several ... High

Package: joserfc
Installed Version: 1.6.5
Vulnerability CVE-2026-49852
Severity: HIGH
Fixed Version: 1.6.8
Link: CVE-2026-49852

Check failure on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS High

Package: starlette
Installed Version: 1.2.1
Vulnerability CVE-2026-54283
Severity: HIGH
Fixed Version: 1.3.1
Link: CVE-2026-54283

Check failure on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

cryptography is a package designed to expose cryptographic primitives ... High

Package: cryptography
Installed Version: 48.0.0
Vulnerability CVE-2026-69247
Severity: HIGH
Fixed Version: 50.0.0
Link: CVE-2026-69247

Check failure on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

python-cryptography is a package designed to expose cryptographic prim ... High

Package: cryptography
Installed Version: 48.0.0
Vulnerability CVE-2026-69249
Severity: HIGH
Fixed Version: 49.0.0
Link: CVE-2026-69249

Check failure on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

python-multipart: Python-Multipart: Denial of Service via crafted form-urlencoded bodies High

Package: python-multipart
Installed Version: 0.0.29
Vulnerability CVE-2026-53539
Severity: HIGH
Fixed Version: 0.0.30
Link: CVE-2026-53539

Check failure on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens High

Package: pyjwt
Installed Version: 2.12.1
Vulnerability CVE-2026-48526
Severity: HIGH
Fixed Version: 2.13.0
Link: CVE-2026-48526

Check failure on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

Vulnerable OpenSSL included in cryptography wheels High

Package: cryptography
Installed Version: 48.0.0
Vulnerability GHSA-537c-gmf6-5ccf
Severity: HIGH
Fixed Version: 48.0.1
Link: GHSA-537c-gmf6-5ccf

Check failure on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

pymdown-extensions: Pymdown-extensions: Denial of Service via Regular Expression Vulnerability High

Package: pymdown-extensions
Installed Version: 10.21.3
Vulnerability CVE-2026-67422
Severity: HIGH
Fixed Version: 11.0.1
Link: CVE-2026-67422

Check warning on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

cryptography is a package designed to expose cryptographic primitives ... Medium

Package: cryptography
Installed Version: 48.0.0
Vulnerability CVE-2026-69248
Severity: MEDIUM
Fixed Version: 49.0.0
Link: CVE-2026-69248

Check warning on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

python-pyjwt: PyJWT: Denial of Service via processing of crafted detached JWS tokens Medium

Package: pyjwt
Installed Version: 2.12.1
Vulnerability CVE-2026-48525
Severity: MEDIUM
Fixed Version: 2.13.0
Link: CVE-2026-48525

Check warning on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

pymdown-extensions: PyMdown Extensions: Information disclosure via path traversal in b64 extension Medium

Package: pymdown-extensions
Installed Version: 10.21.3
Vulnerability CVE-2026-61632
Severity: MEDIUM
Fixed Version: 11.0.0
Link: CVE-2026-61632

Check warning on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

joserfc: joserfc: Resource exhaustion via oversized JSON Web Signature (JWS) payloads Medium

Package: joserfc
Installed Version: 1.6.5
Vulnerability CVE-2026-48990
Severity: MEDIUM
Fixed Version: 1.6.7
Link: CVE-2026-48990

Check warning on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

python-pyjwt: PyJWT: Verifier-side algorithm bypass leads to unauthorized information access Medium

Package: pyjwt
Installed Version: 2.12.1
Vulnerability CVE-2026-48523
Severity: MEDIUM
Fixed Version: 2.13.0
Link: CVE-2026-48523

Check warning on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

python-pyjwt: PyJWT: Server-Side Request Forgery (SSRF) via uncontrolled URL fetching in PyJWKClient Medium

Package: pyjwt
Installed Version: 2.12.1
Vulnerability CVE-2026-48522
Severity: MEDIUM
Fixed Version: 2.13.0
Link: CVE-2026-48522

Check warning on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size Medium

Package: pydantic-settings
Installed Version: 2.14.1
Vulnerability GHSA-4xgf-cpjx-pc3j
Severity: MEDIUM
Fixed Version: 2.14.2
Link: GHSA-4xgf-cpjx-pc3j

Check notice on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

starlette: Starlette: Information disclosure due to improper HTTP request path validation Low

Package: starlette
Installed Version: 1.2.1
Vulnerability CVE-2026-54282
Severity: LOW
Fixed Version: 1.3.0
Link: CVE-2026-54282

Check notice on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

python-multipart: Python-Multipart: Negative Content-Length in parse_form buffers the entire body in memory Low

Package: python-multipart
Installed Version: 0.0.29
Vulnerability CVE-2026-53540
Severity: LOW
Fixed Version: 0.0.31
Link: CVE-2026-53540

Check notice on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

python-multipart: Python-Multipart: Information disclosure due to parser differential in form data handling Low

Package: python-multipart
Installed Version: 0.0.29
Vulnerability CVE-2026-53538
Severity: LOW
Fixed Version: 0.0.30
Link: CVE-2026-53538

Check notice on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

multipart: Python-Multipart: Information disclosure via header parsing discrepancy Low

Package: python-multipart
Installed Version: 0.0.29
Vulnerability CVE-2026-53537
Severity: LOW
Fixed Version: 0.0.30
Link: CVE-2026-53537

Check notice on line 1 in uv.lock

See this annotation in the file changed.

Code scanning / Trivy

python-pyjwt: PyJWT: Denial of Service via unverified JSON Web Token key IDs Low

Package: pyjwt
Installed Version: 2.12.1
Vulnerability CVE-2026-48524
Severity: LOW
Fixed Version: 2.13.0
Link: CVE-2026-48524