-
-
Notifications
You must be signed in to change notification settings - Fork 617
Closed
Description
Will there be a new version released with a new version of the h11 packages that are installed? I see these PRs that were both raised on Apr 24th:
- Bump h11 from 0.14.0 to 0.16.0 in /examples/server/wsgi/django_socketio #1459
- Bump h11 from 0.11.0 to 0.16.0 in /examples/server/asgi #1458
The latest release, however, was on Apr 12th. These PRs fix a critical issue in 0.14 of h11 (https://nvd.nist.gov/vuln/detail/CVE-2025-43859)
Can we get a release that has these fixes in place? Currently it seems like the latest version still has this vulnerable version of the package?
Metadata
Metadata
Assignees
Labels
No labels