Skip to content

fix: patch 7 security alerts (critical + high severity) - #22

Merged
John Kennedy (jkennedyvz) merged 1 commit into
mainfrom
fix/security-alerts-2026-02-24
Feb 25, 2026
Merged

John Kennedy (jkennedyvz) merged 1 commit into
mainfrom
fix/security-alerts-2026-02-24

Conversation

@jkennedyvz

Copy link
Copy Markdown
Contributor

Security Alert Patch

Resolves 7 Dependabot security alerts in the critical + high severity tier.

Packages Updated

Package Old Constraint New Constraint Strategy CVEs Resolved
langchain-core ^0.3.29 ^0.3.81 Direct bump CVE-2025-68664 (critical), CVE-2025-65106 (high)
aiohttp ^3.9.1 ^3.13.3 Direct bump CVE-2025-69223 (high)
h11 (unlisted) >=0.16.0 Constraint CVE-2025-43859 (critical)
urllib3 (unlisted) >=2.6.3 Constraint CVE-2025-66418, CVE-2025-66471, CVE-2026-21441 (high)

CVE Details

  • CVE-2025-68664 (critical) — langchain-core < 0.3.81: serialization injection enables secret extraction via dumps()
  • CVE-2025-43859 (critical) — h11 < 0.16.0: accepts malformed Chunked-Encoding bodies
  • CVE-2025-65106 (high) — langchain-core <= 0.3.79: template injection via attribute access in prompt templates
  • CVE-2025-69223 (high) — aiohttp <= 3.13.2: auto_decompress vulnerable to zip bomb
  • CVE-2025-66418 (high) — urllib3 < 2.6.0: unbounded decompression chain
  • CVE-2025-66471 (high) — urllib3 < 2.6.0: streaming API mishandles highly compressed data
  • CVE-2026-21441 (high) — urllib3 < 2.6.3: decompression-bomb safeguards bypassed when following HTTP redirects

Resolved Lockfile Versions

  • aiohttp → 3.13.3
  • h11 → 0.16.0
  • langchain-core → 0.3.83
  • urllib3 → 2.6.3

Verification

  • All lockfiles regenerated (poetry lock)
  • Linters pass (ruff check, ruff format --check)

🤖 Submitted by langster-patch

Bumps langchain-core, aiohttp, h11, and urllib3 to resolve 7 Dependabot
security alerts across critical and high severity tiers.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@jkennedyvz
John Kennedy (jkennedyvz) merged commit a65c1fb into main Feb 25, 2026
17 checks passed
@jkennedyvz
John Kennedy (jkennedyvz) deleted the fix/security-alerts-2026-02-24 branch February 25, 2026 02:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant