Skip to content

fix(deps): vuln minor upgrades — 5 packages (minor: 4 · patch: 1) [providers/fab] - #39

Draft
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/uv/fab/1-1783382870
Draft

fix(deps): vuln minor upgrades — 5 packages (minor: 4 · patch: 1) [providers/fab]#39
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/uv/fab/1-1783382870

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown

Summary: Critical-severity security update — 5 packages upgraded (MINOR changes included)

Manifests changed:

  • providers/fab (uv)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
apache-airflow 3.0.2 3.2.2 minor Direct 7 CRITICAL, 11 HIGH, 34 MEDIUM, 3 LOW
authlib 1.0.0 1.7.2 minor Direct 3 CRITICAL, 11 HIGH, 9 MEDIUM
pyjwt 2.11.0 2.13.0 minor Direct 5 HIGH, 6 MEDIUM, 2 LOW
flask 2.2.1 2.2.5 patch Direct 3 HIGH, 2 LOW
msgpack 1.0.0 1.2.1 minor Direct 1 HIGH

Security Details

🚨 Critical & High Severity (41 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
apache-airflow PYSEC-2026-184 critical - 3.0.2 3.2.2 -
apache-airflow GHSA-j69x-v4wc-3fpf CRITICAL Apache Airflow Sqoop Provider Improper Input Validation vulnerability 3.0.2 - -
apache-airflow PYSEC-2026-275 critical Apache Airflow Sqoop Provider Improper Input Validation vulnerability 3.0.2 - -
apache-airflow PYSEC-2023-314 critical - 3.0.2 3.1.1 -
apache-airflow GHSA-c92r-g8j5-vhcx CRITICAL Apache Airflow: JWT token still valid after logout 3.0.2 3.2.0 -
apache-airflow CVE-2023-25693 critical - 3.0.2 - -
apache-airflow PYSEC-2026-269 CRITICAL Apache Airflow: JWT token still valid after logout 3.0.2 3.2.0 -
authlib PYSEC-2026-287 critical Authlib JWS JWK Header Injection: Signature Verification Bypass 1.0.0 1.6.9 -
authlib CVE-2026-27962 critical Authlib JWS JWK Header Injection: Signature Verification Bypass 1.0.0 - -
authlib GHSA-wvwj-cvrp-7pv5 CRITICAL Authlib JWS JWK Header Injection: Signature Verification Bypass 1.0.0 1.6.9 -
apache-airflow GHSA-7c2f-r6gc-h92h HIGH Apache Airflow proxy credentials for various providers might leak in task logs 3.0.2 3.1.6 -
apache-airflow GHSA-q2hg-643c-gw8h HIGH Apache Airflow: RCE by race condition in example_xcom dag 3.0.2 3.2.0 -
apache-airflow PYSEC-2026-10 high - 3.0.2 3.1.6 -
apache-airflow PYSEC-2026-16 HIGH - 3.0.2 3.1.8 -
apache-airflow GHSA-4fhm-p86v-hwpx HIGH Apache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applications 3.0.2 3.1.8 -
apache-airflow GHSA-4m3h-wp5w-5hqh HIGH Apache Airflow: Wildcard DagVersion Listing Bypasses Per‑DAG RBAC and Leaks Metadata 3.0.2 3.1.8 -
apache-airflow CVE-2026-28779 HIGH - 3.0.2 - -
apache-airflow GHSA-6ffj-2wg2-w45j HIGH Apache Airflow allows code execution through crafted XCom payloads 3.0.2 - -
apache-airflow PYSEC-2026-13 HIGH - 3.0.2 3.2.0 -
apache-airflow CVE-2025-68675 high - 3.0.2 - -
apache-airflow PYSEC-2026-186 high - 3.0.2 3.2.2 -
authlib GHSA-m344-f55w-2m6j HIGH Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding 1.0.0 1.6.9 -
authlib PYSEC-2024-52 high - 1.0.0 1.3.1 -
authlib GHSA-pq5p-34cr-23v9 HIGH Authlib is vulnerable to Denial of Service via Oversized JOSE Segments 1.0.0 1.6.5 -
authlib CVE-2026-28498 HIGH Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding 1.0.0 - -
authlib CVE-2026-28490 HIGH Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle 1.0.0 - -
authlib CVE-2025-59420 HIGH Authlib: JWS/JWT accepts unknown crit headers (RFC violation → possible authz bypass) 1.0.0 - -
authlib GHSA-9ggr-2464-2j32 HIGH Authlib: JWS/JWT accepts unknown crit headers (RFC violation → possible authz bypass) 1.0.0 1.6.4 -
authlib CVE-2024-37568 high - 1.0.0 - -
authlib GHSA-5357-c2jx-v7qh HIGH Authlib has algorithm confusion with asymmetric public keys 1.0.0 1.3.1 -
authlib CVE-2025-61920 HIGH Authlib is vulnerable to Denial of Service via Oversized JOSE Segments 1.0.0 - -
authlib GHSA-7432-952r-cw78 HIGH Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle 1.0.0 1.6.9 -
flask GHSA-m2qf-hxjv-5gpq HIGH Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header 2.2.1 2.3.2 -
flask CVE-2023-30861 high Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie header 2.2.1 - -
flask PYSEC-2023-62 high - 2.2.1 70f906c51ce49c485f1d355703e9cc3386b1cc2b -
msgpack GHSA-6v7p-g79w-8964 HIGH MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error 1.0.0 1.2.1 -
pyjwt GHSA-752w-5fwx-jx9f HIGH PyJWT accepts unknown crit header extensions 2.11.0 2.12.0 -
pyjwt PYSEC-2026-179 HIGH - 2.11.0 2.13.0 -
pyjwt GHSA-xgmm-8j9v-c9wx HIGH PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed 2.11.0 2.13.0 -
pyjwt PYSEC-2026-120 high - 2.11.0 2.12.0 -
pyjwt CVE-2026-32597 high PyJWT accepts unknown crit header extensions (RFC 7515 §4.1.11 MUST violation) 2.11.0 - -
ℹ️ Other Vulnerabilities (56)
Package CVE Severity Summary Unsafe Version Fixed In Case
apache-airflow PYSEC-2025-85 medium - 3.0.2 - -
apache-airflow PYSEC-2026-15 medium - 3.0.2 3.1.8 -
apache-airflow PYSEC-2026-172 medium - 3.0.2 3.2.2 -
apache-airflow CVE-2026-28563 medium - 3.0.2 - -
apache-airflow PYSEC-2026-12 medium - 3.0.2 3.1.7 -
apache-airflow PYSEC-2026-14 medium - 3.0.2 3.1.8 -
apache-airflow CVE-2026-24098 medium - 3.0.2 - -
apache-airflow PYSEC-2026-181 medium - 3.0.2 3.2.2 -
apache-airflow PYSEC-2026-171 medium - 3.0.2 3.2.2 -
apache-airflow PYSEC-2026-173 medium - 3.0.2 3.2.2 -
apache-airflow PYSEC-2026-187 medium - 3.0.2 3.2.2 -
apache-airflow CVE-2025-54831 medium - 3.0.2 - -
apache-airflow CVE-2026-26929 medium - 3.0.2 - -
apache-airflow CVE-2025-54941 MODERATE - 3.0.2 - -
apache-airflow PYSEC-2026-8 MODERATE - 3.0.2 3.2.0 -
apache-airflow GHSA-q475-2pgm-7hvp MODERATE Apache Airflow: Connection sensitive details exposed to users with READ permissions 3.0.2 3.0.4 -
apache-airflow GHSA-gp5f-cx7h-8q6f MODERATE Apache Airflow's create action can upsert existing Pools/Connections/Variables 3.0.2 3.1.1 -
apache-airflow GHSA-p3v3-229h-mc63 MODERATE Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance record 3.0.2 3.2.1rc1 -
apache-airflow GHSA-w7cf-2pmc-5m4c MODERATE Apache Airflow exposes SQL stack trace despite "api/expose_stack_traces" set to false 3.0.2 - -
apache-airflow CVE-2025-62402 MODERATE - 3.0.2 - -
apache-airflow GHSA-273c-4g26-4jpm MODERATE Apache Airflow /api/v2/dagReports executes DAG Python in API 3.0.2 3.1.1 -
apache-airflow GHSA-4g48-54q2-fg7q MODERATE Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access 3.0.2 3.1.8 -
apache-airflow GHSA-phv5-vq5p-qhp7 MODERATE Apache Airflow: JWT token appearing in logs 3.0.2 3.2.0 -
apache-airflow GHSA-v3c9-j6h9-66v4 MODERATE Apache Airflow has a command injection vulnerability in "example_dag_decorator" 3.0.2 3.0.5 -
apache-airflow CVE-2025-62503 MODERATE - 3.0.2 - -
apache-airflow GHSA-w7rc-q6cm-f5gm MODERATE Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions 3.0.2 3.2.1rc1 -
apache-airflow PYSEC-2026-21 MODERATE - 3.0.2 3.2.0 -
apache-airflow CVE-2025-65995 MODERATE - 3.0.2 - -
apache-airflow GHSA-gfw7-2v73-69wg MODERATE Apache Airflow error reporting may expose full kwargs 3.0.2 2.11.1 -
apache-airflow GHSA-r7vr-m4jw-r794 MODERATE Apache Airflow has an authorization bypass in DagRun wait endpoint 3.0.2 3.2.0 -
apache-airflow GHSA-5g2w-9f8g-g5q7 MODERATE Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated Users 3.0.2 3.1.7 -
apache-airflow PYSEC-2026-18 MODERATE - 3.0.2 3.2.0 -
apache-airflow GHSA-x3fv-96qh-67m7 MODERATE Apache Airflow: DAG authorization bypass 3.0.2 3.1.8 -
apache-airflow GHSA-j86x-fwp2-qh7v MODERATE Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI 3.0.2 3.2.0 -
authlib PYSEC-2026-188 MODERATE - 1.0.0 1.6.12 -
authlib CVE-2025-62706 MODERATE Authlib : JWE zip=DEF decompression bomb enables DoS 1.0.0 - -
authlib GHSA-r95x-qfjj-fjj2 MODERATE Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect 1.0.0 1.7.1 -
authlib CVE-2025-68158 MODERATE Authlib: 1-click Account Takeover 1.0.0 - -
authlib GHSA-w8p2-r796-3vmq MODERATE Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type 1.0.0 1.6.10 -
authlib PYSEC-2026-25 MODERATE - 1.0.0 1.6.11 -
authlib GHSA-jj8c-mmj3-mmgv MODERATE Authlib: Cross-site request forging when using cache 1.0.0 1.6.11 -
authlib GHSA-g7f3-828f-7h7m MODERATE Authlib : JWE zip=DEF decompression bomb enables DoS 1.0.0 1.6.5 -
authlib GHSA-fg6f-75jq-6523 MODERATE Authlib has 1-click Account Takeover vulnerability 1.0.0 1.6.6 -
pyjwt GHSA-993g-76c3-p5m4 MODERATE PyJWKClient: missing scheme allowlist enables CVE-2024-21643-class SSRF + token forgery via file://, ftp://, data: schemes 2.11.0 2.13.0 -
pyjwt GHSA-w7vc-732c-9m39 MODERATE PyJWT: Unauthenticated DoS via unbounded Base64URL decoding of unused payload segment in b64=false detached JWS 2.11.0 2.13.0 -
pyjwt PYSEC-2026-178 MODERATE - 2.11.0 2.13.0 -
pyjwt GHSA-jq35-7prp-9v3f MODERATE PyJWT: Algorithm allow-list bypass when decoding with PyJWK / PyJWKClient keys 2.11.0 2.13.0 -
pyjwt PYSEC-2026-175 MODERATE - 2.11.0 2.13.0 -
pyjwt PYSEC-2026-176 MODERATE - 2.11.0 2.12.1 -
apache-airflow PYSEC-2026-19 LOW - 3.0.2 3.2.0 -
apache-airflow GHSA-w9r4-94fj-xp69 LOW Apache Airflow Exposes Secrets in Variables Saved as JSON Dictionaries 3.0.2 3.2.0 -
apache-airflow PYSEC-2026-174 low - 3.0.2 3.2.2 -
flask GHSA-68rp-wp8r-4726 LOW Flask session does not add Vary: Cookie header when accessed in some ways 2.2.1 3.1.3 -
flask CVE-2026-27205 LOW Flask session does not add Vary: Cookie header when accessed in some ways 2.2.1 - -
pyjwt PYSEC-2026-177 LOW - 2.11.0 2.13.0 -
pyjwt GHSA-fhv5-28vv-h8m8 LOW PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS) 2.11.0 2.13.0 -
⚠️ Dependencies that have Reached EOL (2)
Dependency Unsafe Version EOL Date New Version Path
msgpack 1.0.0 - 1.2.1 providers/fab/pyproject.toml
pyjwt 2.11.0 - 2.13.0 providers/fab/pyproject.toml

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Author

Auto-rebase complete

Branch is up to date with main — rebased onto b3cc48d.


Auto-Rebase · Add no-auto-rebase to opt out

@dd-octo-sts-aad58d
dd-octo-sts-aad58d Bot force-pushed the engraver-auto-version-upgrade/minorpatch/uv/fab/1-1783382870 branch from 80b6c4a to d85bc96 Compare August 3, 2026 14:57
@datadog-datadog-prod-us1-2

This comment has been minimized.

…rs/fab]

Co-authored-by: dd-octo-sts-aad58d[bot] <266798448+dd-octo-sts-aad58d[bot]@users.noreply.github.com>
@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Author

Auto-rebase complete

Branch is up to date with main — rebased onto 7cdb9ad.


Auto-Rebase · Add no-auto-rebase to opt out

@dd-octo-sts-6354d5
dd-octo-sts-6354d5 Bot force-pushed the engraver-auto-version-upgrade/minorpatch/uv/fab/1-1783382870 branch from d85bc96 to 1d9b0a5 Compare August 10, 2026 12:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants