RUN-3991: Mitigate CVE-2025-66471 by upgrading urllib3 to 2.6.0+ #185
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Summary
This PR mitigates CVE-2025-66471 (CVSS 8.9, High severity) by explicitly requiring urllib3 version 2.6.0 or higher.
Changes
urllib3>=2.6.0to requirements.txtVulnerability Details
Dependency Path
The vulnerable urllib3 2.3.0 was being pulled in through:
Testing
✅ All existing tests pass with urllib3 2.6.1:
Verification
After installing dependencies: