Skip to content

security: upgrade vulnerable dependencies#90

Merged
albertotb merged 1 commit into
mainfrom
security/dependency-updates
Jun 21, 2026
Merged

security: upgrade vulnerable dependencies#90
albertotb merged 1 commit into
mainfrom
security/dependency-updates

Conversation

@komorebi-security-bot

@komorebi-security-bot komorebi-security-bot Bot commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

Direct dependencies

Upgraded

No packages were upgraded.

Transitive dependencies

Upgraded

Package Version Needs Vulnerabilities
starlette 1.0.1 → 1.3.1 1.3.1 CVE-2026-54283 (high): Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
CVE-2026-54282 (low): Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname
CVE-2026-48818 (high): Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
CVE-2026-48817 (medium): Starlette: Arbitrary HTTP method dispatched to HTTPEndpoint attributes via getattr
tornado 6.5.6 → 6.5.7 6.5.7 GHSA-pw6j-qg29-8w7f (medium): Tornado: CurlAsyncHTTPClient leaks per-request credentials on handle reuse

@github-actions github-actions Bot force-pushed the security/dependency-updates branch from ed8cfc5 to 8b8e78e Compare June 21, 2026 05:15
@albertotb albertotb enabled auto-merge (squash) June 21, 2026 10:31
@albertotb albertotb merged commit b9d1c56 into main Jun 21, 2026
2 checks passed
@albertotb albertotb deleted the security/dependency-updates branch June 21, 2026 10:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant