CriticalUpdate urllib3 to fix a critical vulnerability(GHSA-www2)
Fix: 1.239.6/10
Update urllib3 to fix a critical vulnerability(GHSA-www2)
Fix: 1.239.6/10Exposure of Sensitive Information to an Unauthorized Actor in urllib3 urllib3 is declared as ">=1.26,<3" and used as a production PyPI dependency of this repo. Severity: critical (CVSS 9.8). Reported via GHSA-www2-v7xj-xrc6 (GHSA).
Upgrade urllib3 to 1.23 or later — low effort (minor version bump).
to claim this mission.
▸Why this score?
Formula
0.60 × impact (9.8) + 0.40 × ecosystem value (9.4) = 9.6
Impact inputs
- CVSS: 9.8
- Severity: critical
- Dependency type: production
- Advisory age: 2817d
Ecosystem value inputs
- Repo stars: 54,266
- Open issues: 234
- Downstream dependents: 112,450
Effort inputs
- Semver bump: minor
- Migration guide: not tracked yet
Why medium confidence
- · No lock file was parsed for this dependency, so the currently-installed version is estimated from its declared range rather than confirmed.
Source
GHSA advisory GHSA-www2-v7xj-xrc6 for urllib3