[Aikido] Fix 33 security issues in urllib3, jinja2, werkzeug and 7 more - #36
Open
aikido-autofix[bot] wants to merge 1 commit into
Open
aikido-autofix[bot] wants to merge 1 commit into
aikido-autofix[bot] wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Upgrade dependencies to fix critical urllib3 vulnerabilities: unbounded memory allocation in chunk parsing (DoS), HTTPS proxy TLS verification bypass, and unlimited decompression chains (DoS/CPU exhaustion).
✅ 33 CVEs resolved by this upgrade
This PR will resolve the following CVEs:
str.formatmethod and invoking it indirectly through a filter, circumventing Jinja's sandbox restrictions. This enables remote code execution through malicious template manipulation.no_proxymatching logic allows attackers to bypass proxy-based egress controls by using lookalike domain names that match suffix patterns without respecting domain boundaries. This enables direct connections that circumvent SSRF protections and proxy-based security controls.extract_zipped_paths()utility function uses predictable filenames when extracting zip archives to the temp directory, allowing local attackers to pre-create malicious files that get loaded instead of legitimate ones, resulting in arbitrary code execution.fromstringandfromfilefunctions allows arbitrary bytes from untrusted input to be dereferenced as Python objects, leading to memory corruption or process crashes.NPY_ENABLE_CPU_FEATURESandNPY_DISABLE_CPU_FEATURESenvironment variables, causing memory corruption and potential denial of service.inoperator without proper cache control headers.read_sql_table,to_sql, ordelete_rowsmethods.🔗 Related Tasks
🤖 Remediation details
Fix multiple high/medium/low severity vulnerabilities in transitive and direct dependencies
Short summary
This PR remediates security vulnerabilities in nine packages: urllib3, jinja2, werkzeug, pyarrow, requests, numpy, flask, idna, and pandas. Four direct dependency lower bounds were raised in the root
pyproject.toml(flask,pandas,requests,streamlit), anduv.lockwas regenerated to pull every vulnerable transitive package up to its patched floor.urllib3
urllib3is a transitive dependency pulled in viarequests(and transitively viastreamlit). All parent declared ranges already permittedurllib3>=2.8.0, so no manifest edit was required for this package directly; the lockfile was refreshed via--upgrade-package urllib3>=2.8.0as part of the coordinated lock run, resolving it from 2.2.3 to 2.8.0.jinja2
jinja2is a transitive dependency offlask,altair, andpydeck(the latter two viastreamlit). All parent declared ranges already permittedjinja2>=3.1.6, so no manifest edit was needed; the lockfile upgrade resolved it from 3.1.4 to 3.1.6, closing sandbox-escape and code-injection vulnerabilities.werkzeug
werkzeugis a transitive dependency offlask. Flask's declared range (>=3.0.0) already permittedwerkzeug>=3.1.6, so no manifest edit was required; the lockfile upgrade resolved it from 3.0.4 to 3.1.9, addressing multiple request-handling and path-traversal vulnerabilities.pyarrow
pyarrowis a transitive dependency ofstreamlit. Streamlit's declared range (>=7.0) already permittedpyarrow>=23.0.1, so no manifest edit was needed for pyarrow directly; the lockfile upgrade resolved it from 17.0.0 to 25.0.1.requests
requestsis a direct dependency declared inpyproject.toml. Its lower bound was raised from>=2.31.0to>=2.34.0to satisfy the patched floor; the lockfile resolved it to 2.34.2. This also unblocked the transitive upgrade ofurllib3andidna.numpy
numpyis a transitive dependency pulled in viapandas,streamlit,pyarrow, andpydeck. All parent declared ranges already permittednumpy>=2.5.3; the lockfile upgrade resolved it from 2.1.1 to 2.5.3 without any manifest change.flask
flaskis a direct dependency declared inpyproject.toml. Its lower bound was raised from>=3.0.3to>=3.1.3to satisfy the patched floor; the lockfile resolved it to 3.1.3. This bump also enabled the transitive upgrades ofwerkzeugandjinja2to their patched versions.idna
idnais a transitive dependency ofrequests. Therequestsdeclared range (<4,>=2.5) already permittedidna>=3.15; the lockfile upgrade resolved it from 3.10 to 3.20 without a direct manifest change.pandas
pandasis a direct dependency declared inpyproject.toml. Its lower bound was raised from>=2.2.2to>=3.0.4to satisfy the patched floor. Additionally,streamlit's lower bound was raised from>=1.39.0to>=1.56.0becausestreamlit1.39.0 declaredpandas<3, which would have prevented the resolver from selecting any patched pandas version; the lockfile resolved pandas to 3.0.6.Version changes
flask>=3.0.3→ 3.0.3>=3.1.3→ 3.1.3pandas>=2.2.2→ 2.2.2>=3.0.4→ 3.0.6requests>=2.31.0→ 2.32.3>=2.34.0→ 2.34.2streamlit>=1.39.0→ 1.39.0>=1.56.0→ 1.64.0urllib3jinja2werkzeugpyarrownumpyidnaaltairnarwhalsblinkeranyioh11httptoolspython-multipartstarletteuvicornwebsocketscachetoolsgitdbgitpythonmarkdown-it-pymdurlpygmentspytzrichsetuptoolssmmaptenacitytornado