chore(deps)(deps): bump the python-minor-patch group across 1 directory with 12 updates - #1013
chore(deps)(deps): bump the python-minor-patch group across 1 directory with 12 updates#1013dependabot[bot] wants to merge 1 commit into
25 new alerts including 13 high severity security vulnerabilities
New alerts in code changed by this pull request
Security Alerts:
- 13 high
- 7 medium
- 5 low
Alerts not introduced by this pull request might have been detected because the code changes were too large.
See annotations below for details.
Annotations
Check failure on line 1 in uv.lock
Code scanning / Trivy
MCP Python SDK: WebSocket server transport does not support Host/Origin validation High
Check failure on line 1 in uv.lock
Code scanning / Trivy
MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks High
Check failure on line 1 in uv.lock
Code scanning / Trivy
MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal High
Check failure on line 1 in uv.lock
Code scanning / Trivy
soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings High
Check failure on line 1 in uv.lock
Code scanning / Trivy
python-soupsieve: Soupsieve: Denial of Service via crafted CSS selector string High
Check failure on line 1 in uv.lock
Code scanning / Trivy
joserfc is a Python library that provides an implementation of several ... High
Check failure on line 1 in uv.lock
Code scanning / Trivy
starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS High
Check failure on line 1 in uv.lock
Code scanning / Trivy
cryptography is a package designed to expose cryptographic primitives ... High
Check failure on line 1 in uv.lock
Code scanning / Trivy
python-cryptography is a package designed to expose cryptographic prim ... High
Check failure on line 1 in uv.lock
Code scanning / Trivy
python-multipart: Python-Multipart: Denial of Service via crafted form-urlencoded bodies High
Check failure on line 1 in uv.lock
Code scanning / Trivy
python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens High
Check failure on line 1 in uv.lock
Code scanning / Trivy
Vulnerable OpenSSL included in cryptography wheels High
Check failure on line 1 in uv.lock
Code scanning / Trivy
pymdown-extensions: Pymdown-extensions: Denial of Service via Regular Expression Vulnerability High
Check warning on line 1 in uv.lock
Code scanning / Trivy
cryptography is a package designed to expose cryptographic primitives ... Medium
Check warning on line 1 in uv.lock
Code scanning / Trivy
python-pyjwt: PyJWT: Denial of Service via processing of crafted detached JWS tokens Medium
Check warning on line 1 in uv.lock
Code scanning / Trivy
pymdown-extensions: PyMdown Extensions: Information disclosure via path traversal in b64 extension Medium
Check warning on line 1 in uv.lock
Code scanning / Trivy
joserfc: joserfc: Resource exhaustion via oversized JSON Web Signature (JWS) payloads Medium
Check warning on line 1 in uv.lock
Code scanning / Trivy
python-pyjwt: PyJWT: Verifier-side algorithm bypass leads to unauthorized information access Medium
Check warning on line 1 in uv.lock
Code scanning / Trivy
python-pyjwt: PyJWT: Server-Side Request Forgery (SSRF) via uncontrolled URL fetching in PyJWKClient Medium
Check warning on line 1 in uv.lock
Code scanning / Trivy
pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size Medium
Check notice on line 1 in uv.lock
Code scanning / Trivy
starlette: Starlette: Information disclosure due to improper HTTP request path validation Low
Check notice on line 1 in uv.lock
Code scanning / Trivy
python-multipart: Python-Multipart: Negative Content-Length in parse_form buffers the entire body in memory Low
Check notice on line 1 in uv.lock
Code scanning / Trivy
python-multipart: Python-Multipart: Information disclosure due to parser differential in form data handling Low
Check notice on line 1 in uv.lock
Code scanning / Trivy
multipart: Python-Multipart: Information disclosure via header parsing discrepancy Low
Check notice on line 1 in uv.lock
Code scanning / Trivy
python-pyjwt: PyJWT: Denial of Service via unverified JSON Web Token key IDs Low