fix: resolve CVE-2026-42561 — bump python-multipart to 0.0.32 - #2989
fix: resolve CVE-2026-42561 — bump python-multipart to 0.0.32#2989sriroopar wants to merge 1 commit into
Conversation
Bumps python-multipart from 0.0.22 to 0.0.32 to address a high-severity DoS vulnerability (CVSS 7.5) in multipart header parsing. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (2)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Enterprise Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
@sriroopar: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
Updates requirements.hashes.source.txt for CVE-2026-42561. Supersedes openshift#2989 — uv.lock already resolved to 0.0.32. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Superseded by #2996. The deps bump already resolves #2996 can be closed in favour of the combined deps bump + CVE fix. |
|
deps bumping PR: #2996 |
|
@onmete: Closed this PR. DetailsIn response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Bumps python-multipart from 0.0.22 to 0.0.32 to address a high-severity DoS vulnerability (CVSS 7.5) in multipart header parsing.
Description
Type of change
Related Tickets & Documents
Checklist before requesting a review
Testing