Skip to content

Fix CVE-2026-21441: Update urllib3 to 2.6.3#690

Merged
blattms merged 1 commit intoOPM:mainfrom
hakonhagland:fix_urllib
Jan 22, 2026
Merged

Fix CVE-2026-21441: Update urllib3 to 2.6.3#690
blattms merged 1 commit intoOPM:mainfrom
hakonhagland:fix_urllib

Conversation

@hakonhagland
Copy link
Collaborator

@hakonhagland hakonhagland commented Jan 8, 2026

Addresses Dependabot security alert #22 and Dependabot security alert #23. The vulnerability allowed decompression-bomb attacks when following HTTP redirects in urllib3's streaming API, potentially causing excessive resource consumption.

Addresses Dependabot security alert OPM#23. The vulnerability allowed
decompression-bomb attacks when following HTTP redirects in urllib3's
streaming API, potentially causing excessive resource consumption.
@blattms blattms merged commit a42f4b5 into OPM:main Jan 22, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants