Skip to content

Conversation

@fdevans
Copy link
Contributor

@fdevans fdevans commented Dec 8, 2025

Summary

This PR mitigates CVE-2025-66471 (CVSS 8.9, High severity) by explicitly requiring urllib3 version 2.6.0 or higher.

Changes

  • Added urllib3>=2.6.0 to requirements.txt
  • This ensures the secure version is installed even when pulled as a transitive dependency

Vulnerability Details

  • CVE: CVE-2025-66471
  • CWE: CWE-409
  • CVSS Score: 8.9 (High)
  • Affected: urllib3 < 2.6.0
  • Fixed in: urllib3 2.6.0+

Dependency Path

The vulnerable urllib3 2.3.0 was being pulled in through:

Testing

✅ All existing tests pass with urllib3 2.6.1:

pytest: 4/4 tests passed (100%)

Verification

After installing dependencies:

$ pip show urllib3
Name: urllib3
Version: 2.6.1

- Add explicit urllib3>=2.6.0 requirement to fix security vulnerability
- CVE-2025-66471 (CVSS 8.9) affects urllib3 < 2.6.0
- All tests pass with the upgraded version
Copilot AI review requested due to automatic review settings December 8, 2025 18:30
Copy link
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.


💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@fdevans fdevans merged commit b681764 into master Dec 12, 2025
3 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants