Skip to content

fix(deps): PyJWT 2.15.0 and urllib3 2.8.0 for newly published CVEs - #411

Merged
jwvanderstam merged 1 commit into
mainfrom
fix/deps-pyjwt-urllib3-cves
Oct 1, 2026
Merged

jwvanderstam merged 1 commit into
mainfrom
fix/deps-pyjwt-urllib3-cves

Conversation

@jwvanderstam

Copy link
Copy Markdown
Owner

Merge this first. Newly published advisories turned pip-audit red on main and on every open PR. #410's latest run failed on it, and the others will fail on their next run.

Package Was Now Advisories
PyJWT (direct) 2.14.0 2.15.0 CVE-2026-101918
urllib3 (transitive) 2.7.0 2.8.0 CVE-2026-97687, CVE-2026-97688, CVE-2026-97689

How

  • PyJWT is bumped in requirements.in.
  • urllib3 moved by a targeted pip-compile --upgrade-package on Linux (python:3.12-slim, the documented command).
  • No other pin changed in either lock. The diff is 4 lines across the 3 files.

Dependabot's #401 carries the PyJWT bump but not urllib3, so it would stay red. Close it once this lands, or let Dependabot rebase it into a no-op.

Verified

  • pip-audit -r requirements.txt: No known vulnerabilities found.
  • On the new pins, the auth, token-verification, one-resolver, security-contract and safe-fetch suites pass: 72 of 72. PyJWT verifies session tokens, and urllib3 sits under the HTTP clients.

🤖 Generated with Claude Code

CVE-2026-101918 (PyJWT 2.14.0) and CVE-2026-97687/-97688/-97689 (urllib3
2.7.0) were published overnight and turned pip-audit red on main and on every
open PR. PyJWT is bumped in requirements.in; urllib3 is transitive and moved by
a targeted pip-compile --upgrade-package on Linux. No other pin changed in
either lock. Dependabot #401 carries PyJWT but not urllib3.

pip-audit clean; the auth, token and safe-fetch suites pass on the new pins.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@sonarqubecloud

Copy link
Copy Markdown

@jwvanderstam
jwvanderstam merged commit 1f7c7aa into main Oct 1, 2026
15 checks passed
@jwvanderstam
jwvanderstam deleted the fix/deps-pyjwt-urllib3-cves branch October 1, 2026 07:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant