Skip to content

Fix CVE-2025-66418, CVE-2025-66471, CVE-2026-21441: Update urllib3 to 2.6.3#20

Merged
blattms merged 1 commit intoOPM:masterfrom
hakonhagland:fix_urrlib
Jan 22, 2026
Merged

Fix CVE-2025-66418, CVE-2025-66471, CVE-2026-21441: Update urllib3 to 2.6.3#20
blattms merged 1 commit intoOPM:masterfrom
hakonhagland:fix_urrlib

Conversation

@hakonhagland
Copy link
Collaborator

Addresses Dependabot security alerts #11, #12, and #13. These vulnerabilities allowed decompression-bomb attacks through various vectors in urllib3's streaming API.

… 2.6.3

Addresses Dependabot security alerts OPM#11, OPM#12, and OPM#13. These
vulnerabilities allowed decompression-bomb attacks through various
vectors in urllib3's streaming API.
@blattms blattms merged commit 9456219 into OPM:master Jan 22, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants