Skip to content

Lock urllib3 2.8.0, oauthlib 4.0.0 and virtualenv 21.14.1 for eight advisories - #1

Merged
mahdi-shafiei merged 2 commits into
mainfrom
fix/urllib3-oauthlib
Sep 30, 2026
Merged

mahdi-shafiei merged 2 commits into
mainfrom
fix/urllib3-oauthlib

Conversation

@mahdi-shafiei

@mahdi-shafiei mahdi-shafiei commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

The weekly Security job fails on four advisories in the lock. This locks the fixed releases:

package from to advisories
urllib3 2.7.0 2.8.0 CVE-2026-97687, CVE-2026-97688, CVE-2026-97689
oauthlib 3.3.1 4.0.0 CVE-2026-49265

oauthlib reaches the lock through blackjax -> fastprogress -> python-fasthtml 0.12.48, which bounds it from neither side. python-fasthtml imports only oauthlib.oauth2.WebApplicationClient. A probe with python-fasthtml 0.12.48, oauthlib 4.0.0 and fastprogress 1.1.6 shows its request URI and body preparation, GitHubAppClient.login_link, and fastprogress's progress_bar working unchanged.

Verification

  • The Security job's own audit (uv export --frozen --all-extras --all-groups --no-emit-project, then uvx pip-audit -r ... --disable-pip --no-deps) reports 4 known vulnerabilities in 2 packages on main, and "No known vulnerabilities found" on this branch.
  • The exported requirement sets differ only in these two pins.
  • pre-commit run --all-files passes.

virtualenv 21.14.1 (PYSEC-2026-4011 to -4014)

Four advisories published 2026-09-30 affect every virtualenv release below 21.7.13 (OSV: introduced 0; fixed 21.7.11 to 21.7.13). virtualenv reaches the lock only through pre-commit. Audited with a fresh pip-audit cache: the old lock reports the four, the new one none.

urllib3 2.8.0 fixes CVE-2026-97687, -97688 and -97689; oauthlib 4.0.0
fixes CVE-2026-49265. oauthlib reaches the lock through blackjax ->
fastprogress -> python-fasthtml, which bounds it from neither side.
python-fasthtml imports only oauthlib.oauth2.WebApplicationClient; its
request URI and body preparation and fastprogress's progress bar work
unchanged under 4.0.0. No other package moves.
virtualenv reaches the lock through pre-commit; every release below
21.7.13 is affected. python-discovery 1.6.1 moves with it. The Security
job's audit over the whole lock reports no known vulnerability.
@mahdi-shafiei mahdi-shafiei changed the title Lock urllib3 2.8.0 and oauthlib 4.0.0 for four advisories Lock urllib3 2.8.0, oauthlib 4.0.0 and virtualenv 21.14.1 for eight advisories Sep 30, 2026
@mahdi-shafiei
mahdi-shafiei merged commit 5c97ae1 into main Sep 30, 2026
7 checks passed
@mahdi-shafiei
mahdi-shafiei deleted the fix/urllib3-oauthlib branch September 30, 2026 18:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant