Skip to content

Security/upgrade requests urllib3 CVE fix#894

Merged
mayankmendix merged 3 commits into
mendix:developfrom
bhavinshah-mendix:security/upgrade-requests-urllib3-CVE-fix
May 25, 2026
Merged

Security/upgrade requests urllib3 CVE fix#894
mayankmendix merged 3 commits into
mendix:developfrom
bhavinshah-mendix:security/upgrade-requests-urllib3-CVE-fix

Conversation

@bhavinshah-mendix
Copy link
Copy Markdown
Contributor

No description provided.

bhavinshah-mendix and others added 3 commits May 25, 2026 14:29
Fixes high-severity CVEs:
- CVE-2026-25645 (requests): Fixed in 2.33.0+
- GHSA-mf9v-mfxr-j63j (urllib3): Streaming API decompression issue
- GHSA-qccp-gfcp-xxvc (urllib3): Cross-origin redirect header leakage

Changes:
- requests: 2.32.5 → 2.34.2
- urllib3: 2.6.3 → 2.7.0
- charset-normalizer: 2.0.3 → 3.4.7 (transitive)
- idna: 3.10 → 3.15 (transitive)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
   - CVE-2026-25645 (requests): Fixed in 2.33.0+
   - GHSA-mf9v-mfxr-j63j (urllib3): Streaming API decompression issue
   - GHSA-qccp-gfcp-xxvc (urllib3): Cross-origin redirect header leakage
@mayankmendix mayankmendix merged commit ef8bec4 into mendix:develop May 25, 2026
26 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants