Skip to content

[Aikido] Fix 33 security issues in urllib3, jinja2, werkzeug and 7 more - #36

Open
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-update-packages-130147538-j5an
Open

aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/aikido-security-update-packages-130147538-j5an

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Oct 1, 2026

Copy link
Copy Markdown

Upgrade dependencies to fix critical urllib3 vulnerabilities: unbounded memory allocation in chunk parsing (DoS), HTTPS proxy TLS verification bypass, and unlimited decompression chains (DoS/CPU exhaustion).

✅ 33 CVEs resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
AIKIDO-2026-740601
HIGH
[urllib3] Unbounded chunk-size line reading in HTTP responses allows remote servers to cause denial of service by exhausting client memory through oversized or malformed chunk headers without proper termination.
CVE-2026-97689
HIGH
[urllib3] Unbounded memory allocation vulnerability in chunked transfer encoding parser allows a malicious server to exhaust client memory by sending an unterminated chunk-size line, causing denial of service.
AIKIDO-2026-499214
HIGH
[urllib3] TLS certificate validation bypass allowing an attacker between the client and HTTPS proxy to present a certificate satisfying destination server checks instead of proxy-specific validation requirements. This occurs when distinct verification settings are configured for proxy versus destination connections.
CVE-2026-97687
HIGH
[urllib3] Target-server TLS settings are incorrectly applied to HTTPS proxy connections, allowing attackers to intercept proxied traffic by impersonating the proxy after certificate verification is disabled. This enables traffic observation, modification, or theft of client certificates.
CVE-2025-66418
HIGH
[urllib3] An unbounded decompression chain vulnerability allows malicious servers to insert unlimited compression steps, causing excessive CPU usage and memory allocation. This leads to denial of service through resource exhaustion.
CVE-2025-66471
HIGH
[urllib3] The Streaming API improperly handles highly compressed data, allowing attackers to cause excessive CPU usage and massive memory allocation through decompression of small compressed payloads. This results in a denial-of-service vulnerability via resource exhaustion.
CVE-2026-21441
HIGH
[urllib3] A decompression bomb vulnerability in urllib3's streaming API allows malicious servers to trigger excessive resource consumption by sending compressed redirect responses that are fully decompressed without respecting read limits, potentially causing denial of service.
CVE-2025-50181
MEDIUM
[urllib3] A vulnerability allows disabling redirects for all requests through improper PoolManager instantiation with retries configuration, leaving applications vulnerable to SSRF and open redirect attacks despite attempting to mitigate them at the PoolManager level.
CVE-2025-50182
MEDIUM
[urllib3] A vulnerability allows uncontrolled HTTP redirects in browser and Node.js environments when using Pyodide, as redirect parameters are ignored and the runtime determines redirect behavior instead, potentially enabling open redirect attacks or information disclosure.
AIKIDO-2026-499458
MEDIUM
[urllib3] HTTP CONNECT tunnel requests can be manipulated through carriage-return/line-feed injection in host or header values, allowing request smuggling and header injection past proxy validation. The vulnerability enables attackers to alter tunnel requests or bypass proxy security controls through externally-influenced data.
AIKIDO-2026-193495
MEDIUM
[urllib3] HTTPConnection.getresponse() fails to normalize obsolete folded headers, allowing servers to embed literal CRLF sequences in header values like Set-Cookie. This can lead to header injection or cookie boundary misinterpretation when headers are split, logged, or forwarded.
CVE-2026-44431
MEDIUM
[urllib3] is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive headers. This vulnerability is fixed in 2.7.0.
CVE-2024-56201
HIGH
[jinja2] A compiler bug allows attackers who control both template content and filename to execute arbitrary Python code, bypassing Jinja's sandbox protections. This impacts applications that process untrusted templates where the attacker can specify the template filename.
CVE-2025-27516
HIGH
[jinja2] Sandbox bypass in the |attr filter allows attackers controlling template content to execute arbitrary Python code by accessing restricted string methods like format. This vulnerability affects applications that execute untrusted templates.
CVE-2024-56326
HIGH
[jinja2] Sandbox bypass in template processing allows arbitrary Python code execution through indirect calls to str.format method via custom filters when attacker controls template content.
AIKIDO-2024-10560
MEDIUM
[jinja2] A sandbox bypass vulnerability allows attackers to execute arbitrary code by storing a reference to the str.format method and invoking it indirectly through a filter, circumventing Jinja's sandbox restrictions. This enables remote code execution through malicious template manipulation.
CVE-2024-49767
HIGH
[werkzeug] The MultiPartParser is vulnerable to a denial of service attack where specially crafted multipart form submissions cause excessive memory allocation, consuming 3-8x the upload size in RAM with no upper limit.
CVE-2026-27199
MEDIUM
[werkzeug] A path traversal vulnerability in the safe_join function allows Windows device names (like NUL) as filenames when preceded by path segments, causing file read operations to hang indefinitely when serving files through send_from_directory on Windows systems.
CVE-2024-49766
MEDIUM
[werkzeug] safe_join() fails to properly validate UNC paths on Windows with Python < 3.11, allowing path traversal attacks that could expose unintended files. This vulnerability enables unauthorized access to sensitive data through improper path sanitization.
CVE-2025-66221
MEDIUM
[werkzeug] The safe_join function fails to block Windows device names (CON, AUX, etc.), allowing attackers to request these special paths through send_from_directory, causing indefinite hangs when reading files on Windows systems (Denial of Service).
CVE-2026-21860
MEDIUM
[werkzeug] The safe_join function fails to properly validate Windows device names (like CON, AUX) when they have file extensions or trailing spaces, allowing attackers to bypass path restrictions and access restricted files on Windows systems.
CVE-2026-25087
HIGH
[pyarrow] Use After Free vulnerability in Arrow C++ IPC file reader with pre-buffering enabled and variadic buffers, causing potential remote code execution, denial of service, or memory corruption through dangling pointer writes.
AIKIDO-2026-106840
MEDIUM
[requests] Proxy bypass vulnerability in no_proxy matching logic allows attackers to bypass proxy-based egress controls by using lookalike domain names that match suffix patterns without respecting domain boundaries. This enables direct connections that circumvent SSRF protections and proxy-based security controls.
CVE-2026-25645
MEDIUM
[requests] The extract_zipped_paths() utility function uses predictable filenames when extracting zip archives to the temp directory, allowing local attackers to pre-create malicious files that get loaded instead of legitimate ones, resulting in arbitrary code execution.
CVE-2024-47081
MEDIUM
[requests] A URL parsing vulnerability allows maliciously-crafted URLs to leak .netrc credentials to third parties. This could enable credential theft and unauthorized access to authenticated services.
AIKIDO-2026-775417
MEDIUM
[numpy] Improper validation of dtype object references in fromstring and fromfile functions allows arbitrary bytes from untrusted input to be dereferenced as Python objects, leading to memory corruption or process crashes.
AIKIDO-2026-344675
MEDIUM
[numpy] A vulnerability in casting byte strings to StringDType fails to validate UTF-8 encoding, allowing malformed sequences to cause out-of-bounds access or hangs in subsequent string operations. The fix adds UTF-8 validation and bounds checking to reject invalid input at cast time.
AIKIDO-2026-795744
MEDIUM
[numpy] A buffer overflow vulnerability in timedelta-to-string casting ignores requested string width, causing out-of-bounds writes that corrupt heap memory and lead to denial of service or potential code execution.
AIKIDO-2026-125890
LOW
[numpy] Stack buffer overflow in CPU feature parsing during import via NPY_ENABLE_CPU_FEATURES and NPY_DISABLE_CPU_FEATURES environment variables, causing memory corruption and potential denial of service.
CVE-2026-27205
MEDIUM
[flask] A vulnerability in session object access fails to set the Vary: Cookie header in certain cases, allowing sensitive cached responses to be served to unauthorized users. This information disclosure issue occurs when applications access sessions through specific methods like the Python in operator without proper cache control headers.
CVE-2026-45409
LOW
[idna] A denial-of-service vulnerability exists where specially crafted payloads with repeated Unicode characters cause excessive processing time in the IDNA encoding function. Enforcing a 253-character domain length limit before processing mitigates the issue.
AIKIDO-2026-367021
LOW
[pandas] SQL injection vulnerability in ADBC database operations where unquoted table and schema identifiers are interpolated directly into SQL statements, allowing attackers to execute arbitrary SQL commands through read_sql_table, to_sql, or delete_rows methods.
AIKIDO-2024-10410
LOW
[Werkzeug] Inadequate PBKDF2 iteration count in default encryption configuration allows attackers to perform faster brute force and dictionary attacks against encrypted data.
🔗 Related Tasks
🤖 Remediation details

Fix multiple high/medium/low severity vulnerabilities in transitive and direct dependencies

Short summary

This PR remediates security vulnerabilities in nine packages: urllib3, jinja2, werkzeug, pyarrow, requests, numpy, flask, idna, and pandas. Four direct dependency lower bounds were raised in the root pyproject.toml (flask, pandas, requests, streamlit), and uv.lock was regenerated to pull every vulnerable transitive package up to its patched floor.


urllib3

urllib3 is a transitive dependency pulled in via requests (and transitively via streamlit). All parent declared ranges already permitted urllib3>=2.8.0, so no manifest edit was required for this package directly; the lockfile was refreshed via --upgrade-package urllib3>=2.8.0 as part of the coordinated lock run, resolving it from 2.2.3 to 2.8.0.

jinja2

jinja2 is a transitive dependency of flask, altair, and pydeck (the latter two via streamlit). All parent declared ranges already permitted jinja2>=3.1.6, so no manifest edit was needed; the lockfile upgrade resolved it from 3.1.4 to 3.1.6, closing sandbox-escape and code-injection vulnerabilities.

werkzeug

werkzeug is a transitive dependency of flask. Flask's declared range (>=3.0.0) already permitted werkzeug>=3.1.6, so no manifest edit was required; the lockfile upgrade resolved it from 3.0.4 to 3.1.9, addressing multiple request-handling and path-traversal vulnerabilities.

pyarrow

pyarrow is a transitive dependency of streamlit. Streamlit's declared range (>=7.0) already permitted pyarrow>=23.0.1, so no manifest edit was needed for pyarrow directly; the lockfile upgrade resolved it from 17.0.0 to 25.0.1.

requests

requests is a direct dependency declared in pyproject.toml. Its lower bound was raised from >=2.31.0 to >=2.34.0 to satisfy the patched floor; the lockfile resolved it to 2.34.2. This also unblocked the transitive upgrade of urllib3 and idna.

numpy

numpy is a transitive dependency pulled in via pandas, streamlit, pyarrow, and pydeck. All parent declared ranges already permitted numpy>=2.5.3; the lockfile upgrade resolved it from 2.1.1 to 2.5.3 without any manifest change.

flask

flask is a direct dependency declared in pyproject.toml. Its lower bound was raised from >=3.0.3 to >=3.1.3 to satisfy the patched floor; the lockfile resolved it to 3.1.3. This bump also enabled the transitive upgrades of werkzeug and jinja2 to their patched versions.

idna

idna is a transitive dependency of requests. The requests declared range (<4,>=2.5) already permitted idna>=3.15; the lockfile upgrade resolved it from 3.10 to 3.20 without a direct manifest change.

pandas

pandas is a direct dependency declared in pyproject.toml. Its lower bound was raised from >=2.2.2 to >=3.0.4 to satisfy the patched floor. Additionally, streamlit's lower bound was raised from >=1.39.0 to >=1.56.0 because streamlit 1.39.0 declared pandas<3, which would have prevented the resolver from selecting any patched pandas version; the lockfile resolved pandas to 3.0.6.


Version changes

Package From To Why updated
flask >=3.0.3 → 3.0.3 >=3.1.3 → 3.1.3 Direct CVE fix (manifest lower bound raised)
pandas >=2.2.2 → 2.2.2 >=3.0.4 → 3.0.6 Direct CVE fix (manifest lower bound raised)
requests >=2.31.0 → 2.32.3 >=2.34.0 → 2.34.2 Direct CVE fix (manifest lower bound raised)
streamlit >=1.39.0 → 1.39.0 >=1.56.0 → 1.64.0 Parent bump required to unblock pandas>=3.0.4
urllib3 2.2.3 2.8.0 Transitive CVE fix (via requests / streamlit)
jinja2 3.1.4 3.1.6 Transitive CVE fix (via flask, altair, pydeck)
werkzeug 3.0.4 3.1.9 Transitive CVE fix (via flask)
pyarrow 17.0.0 25.0.1 Transitive CVE fix (via streamlit)
numpy 2.1.1 2.5.3 Transitive CVE fix (via pandas, streamlit, pyarrow, pydeck)
idna 3.10 3.20 Transitive CVE fix (via requests)
altair 5.4.1 6.3.0 Transitive after streamlit bump
narwhals 1.10.0 2.26.0 Transitive after streamlit/altair bump
blinker 1.8.2 1.9.0 Transitive after streamlit bump
anyio — 4.14.2 New transitive dependency of streamlit 1.64.0
h11 — 0.16.0 New transitive dependency of streamlit 1.64.0
httptools — 0.8.0 New transitive dependency of streamlit 1.64.0
python-multipart — 0.0.32 New transitive dependency of streamlit 1.64.0
starlette — 1.7.0 New transitive dependency of streamlit 1.64.0
uvicorn — 0.54.0 New transitive dependency of streamlit 1.64.0
websockets — 16.1.1 New transitive dependency of streamlit 1.64.0
cachetools 5.5.0 — Removed; no longer required by streamlit 1.64.0
gitdb 4.0.11 — Removed; no longer required by streamlit 1.64.0
gitpython 3.1.43 — Removed; no longer required by streamlit 1.64.0
markdown-it-py 3.0.0 — Removed; no longer required by streamlit 1.64.0
mdurl 0.1.2 — Removed; no longer required by streamlit 1.64.0
pygments 2.18.0 — Removed; no longer required by streamlit 1.64.0
pytz 2024.2 — Removed; no longer required by pandas 3.x
rich 13.9.3 — Removed; no longer required by streamlit 1.64.0
setuptools 75.1.0 — Removed; no longer required by streamlit 1.64.0
smmap 5.0.1 — Removed; no longer required by streamlit 1.64.0
tenacity 9.0.0 — Removed; no longer required by streamlit 1.64.0
tornado 6.4.1 — Removed; no longer required by streamlit 1.64.0
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

0 participants