Update dependency urllib3 to v2 #30
Security Report
You have successfully remediated 19 vulnerabilities, but introduced 16 new vulnerabilities in this branch.
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | |
|---|---|---|---|---|---|---|
CVE-2026-21441Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260108131820_SVMMYF/python_RKCEWT/202601081318211/env/lib/python3.9/site-packages/urllib3-1.26.20.dist-info Dependency Hierarchy: -> requests-2.28.2-py3-none-any.whl (Root Library) -> ❌ urllib3-1.26.20-py2.py3-none-any.whl (Vulnerable Library) |
8.6 | Transitive urllib3-1.26.20-py2.py3-none-any.whl |
requests-2.28.2-py3-none-any.whl | Transitive 2.6.3 |
#15 | |
CVE-2025-66471Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260108131820_SVMMYF/python_RKCEWT/202601081318211/env/lib/python3.9/site-packages/urllib3-1.26.20.dist-info Dependency Hierarchy: -> requests-2.28.2-py3-none-any.whl (Root Library) -> ❌ urllib3-1.26.20-py2.py3-none-any.whl (Vulnerable Library) |
8.6 | Transitive urllib3-1.26.20-py2.py3-none-any.whl |
requests-2.28.2-py3-none-any.whl | Transitive urllib3 - 2.6.0,https://github.com/urllib3/urllib3.git - 2.6.0 |
#15 | |
CVE-2025-66418Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260108131820_SVMMYF/python_RKCEWT/202601081318211/env/lib/python3.9/site-packages/urllib3-1.26.20.dist-info Dependency Hierarchy: -> requests-2.28.2-py3-none-any.whl (Root Library) -> ❌ urllib3-1.26.20-py2.py3-none-any.whl (Vulnerable Library) |
8.6 | Transitive urllib3-1.26.20-py2.py3-none-any.whl |
requests-2.28.2-py3-none-any.whl | Transitive https://github.com/urllib3/urllib3.git - 2.6.0,urllib3 - 2.6.0 |
#15 | |
CVE-2023-4807Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260108131820_SVMMYF/python_RKCEWT/202601081318211/env/lib/python3.9/site-packages/cryptography-39.0.0.dist-info Dependency Hierarchy: -> ❌ cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl (Vulnerable Library) |
7.8 | Direct cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl |
cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl | openssl - 1.1.1w | None | |
CVE-2024-6119Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260108131820_SVMMYF/python_RKCEWT/202601081318211/env/lib/python3.9/site-packages/cryptography-39.0.0.dist-info Dependency Hierarchy: -> ❌ cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl (Vulnerable Library) |
7.5 | Direct cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl |
cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl | None | ||
CVE-2024-26130Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260108131820_SVMMYF/python_RKCEWT/202601081318211/env/lib/python3.9/site-packages/cryptography-39.0.0.dist-info Dependency Hierarchy: -> ❌ cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl (Vulnerable Library) |
7.5 | Direct cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl |
cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl | 42.0.4 | None | |
CVE-2023-50782Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260108131820_SVMMYF/python_RKCEWT/202601081318211/env/lib/python3.9/site-packages/cryptography-39.0.0.dist-info Dependency Hierarchy: -> ❌ cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl (Vulnerable Library) |
7.5 | Direct cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl |
cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl | 42.0.0 | None | |
CVE-2023-38325Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260108131820_SVMMYF/python_RKCEWT/202601081318211/env/lib/python3.9/site-packages/cryptography-39.0.0.dist-info Dependency Hierarchy: -> ❌ cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl (Vulnerable Library) |
7.5 | Direct cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl |
cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl | 41.0.2 | None | |
CVE-2023-0286Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260108131820_SVMMYF/python_RKCEWT/202601081318211/env/lib/python3.9/site-packages/cryptography-39.0.0.dist-info Dependency Hierarchy: -> ❌ cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl (Vulnerable Library) |
7.4 | Direct cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl |
cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl | openssl-3.0.8;cryptography - 39.0.1;openssl-src - 111.25.0+1.1.1t,300.0.12+3.0.8,openssl - 3.0.12,openssl - 1.1.1w | None | |
CVE-2023-2650Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260108131820_SVMMYF/python_RKCEWT/202601081318211/env/lib/python3.9/site-packages/cryptography-39.0.0.dist-info Dependency Hierarchy: -> ❌ cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl (Vulnerable Library) |
6.5 | Direct cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl |
cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl | openssl - 1.0.2zh,openssl - 3.1.3,openssl - 1.1.1w,openssl - 3.0.12 | None | |
CVE-2024-3772Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260108131820_SVMMYF/python_RKCEWT/202601081318211/env/lib/python3.9/site-packages/pydantic-1.10.4.dist-info Dependency Hierarchy: -> ❌ pydantic-1.10.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl (Vulnerable Library) |
5.9 | Direct pydantic-1.10.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
pydantic-1.10.4-cp39-cp39-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | 1.10.13 | None | |
CVE-2023-49083Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260108131820_SVMMYF/python_RKCEWT/202601081318211/env/lib/python3.9/site-packages/cryptography-39.0.0.dist-info Dependency Hierarchy: -> ❌ cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl (Vulnerable Library) |
5.9 | Direct cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl |
cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl | 41.0.6 | None | |
CVE-2024-0727Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260108131820_SVMMYF/python_RKCEWT/202601081318211/env/lib/python3.9/site-packages/cryptography-39.0.0.dist-info Dependency Hierarchy: -> ❌ cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl (Vulnerable Library) |
5.5 | Direct cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl |
cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl | 42.0.2 | None | |
CVE-2025-50181Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260108131820_SVMMYF/python_RKCEWT/202601081318211/env/lib/python3.9/site-packages/urllib3-1.26.20.dist-info Dependency Hierarchy: -> requests-2.28.2-py3-none-any.whl (Root Library) -> ❌ urllib3-1.26.20-py2.py3-none-any.whl (Vulnerable Library) |
5.3 | Transitive urllib3-1.26.20-py2.py3-none-any.whl |
requests-2.28.2-py3-none-any.whl | Transitive 2.5.0 |
#15 | |
CVE-2023-3446Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260108131820_SVMMYF/python_RKCEWT/202601081318211/env/lib/python3.9/site-packages/cryptography-39.0.0.dist-info Dependency Hierarchy: -> ❌ cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl (Vulnerable Library) |
5.3 | Direct cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl |
cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl | openssl - 1.1.1w,openssl - 3.1.3 | None | |
CVE-2023-23931Path to dependency file: /requirements.txt Path to vulnerable library: /tmp/ws-ua_20260108131820_SVMMYF/python_RKCEWT/202601081318211/env/lib/python3.9/site-packages/cryptography-39.0.0.dist-info Dependency Hierarchy: -> ❌ cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl (Vulnerable Library) |
4.8 | Direct cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl |
cryptography-39.0.0-cp36-abi3-manylinux_2_28_x86_64.whl | 39.0.1 | None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2023-38325 | cryptography-39.0.0-cp36-abi3-manylinux_2_24_x86_64.whl |
| CVE-2023-45803 | urllib3-1.26.14-py2.py3-none-any.whl |
| CVE-2024-0727 | cryptography-39.0.0-cp36-abi3-manylinux_2_24_x86_64.whl |
| CVE-2026-21441 | urllib3-1.26.14-py2.py3-none-any.whl |
| CVE-2023-3446 | cryptography-39.0.0-cp36-abi3-manylinux_2_24_x86_64.whl |
| CVE-2023-43804 | urllib3-1.26.14-py2.py3-none-any.whl |
| CVE-2023-4807 | cryptography-39.0.0-cp36-abi3-manylinux_2_24_x86_64.whl |
| CVE-2025-66418 | urllib3-1.26.14-py2.py3-none-any.whl |
| CVE-2023-0286 | cryptography-39.0.0-cp36-abi3-manylinux_2_24_x86_64.whl |
| CVE-2023-2650 | cryptography-39.0.0-cp36-abi3-manylinux_2_24_x86_64.whl |
| CVE-2023-50782 | cryptography-39.0.0-cp36-abi3-manylinux_2_24_x86_64.whl |
| CVE-2024-3772 | pydantic-1.10.4-cp37-cp37m-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2025-50181 | urllib3-1.26.14-py2.py3-none-any.whl |
| CVE-2024-37891 | urllib3-1.26.14-py2.py3-none-any.whl |
| CVE-2025-66471 | urllib3-1.26.14-py2.py3-none-any.whl |
| CVE-2024-26130 | cryptography-39.0.0-cp36-abi3-manylinux_2_24_x86_64.whl |
| CVE-2024-6119 | cryptography-39.0.0-cp36-abi3-manylinux_2_24_x86_64.whl |
| CVE-2023-49083 | cryptography-39.0.0-cp36-abi3-manylinux_2_24_x86_64.whl |
| CVE-2023-23931 | cryptography-39.0.0-cp36-abi3-manylinux_2_24_x86_64.whl |
Base branch total remaining vulnerabilities: 39
Base branch commit: null
Total libraries scanned: 27
Scan token: 860adcfd4dc34227b24ea128dcd03b0d