Skip to content

fix(deps): vuln minor: Authlib · patch: pytest [tests/authorization] - #36

Open
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/pip/authorization/1-1783352523
Open

fix(deps): vuln minor: Authlib · patch: pytest [tests/authorization]#36
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
mainfrom
engraver-auto-version-upgrade/minorpatch/pip/authorization/1-1783352523

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown

Summary: Critical-severity security update — 2 packages upgraded (MINOR changes included)

Manifests changed:

  • tests/authorization (pip)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
Authlib 1.3.1 1.7.2 minor Direct 3 CRITICAL, 8 HIGH, 9 MEDIUM
pytest 7.1.2 7.1.3 patch Direct 2 MEDIUM

Security Details

🚨 Critical & High Severity (11 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
Authlib PYSEC-2026-287 critical Authlib JWS JWK Header Injection: Signature Verification Bypass 1.3.1 1.6.9 -
Authlib CVE-2026-27962 critical Authlib JWS JWK Header Injection: Signature Verification Bypass 1.3.1 - -
Authlib GHSA-wvwj-cvrp-7pv5 CRITICAL Authlib JWS JWK Header Injection: Signature Verification Bypass 1.3.1 1.6.9 -
Authlib GHSA-pq5p-34cr-23v9 HIGH Authlib is vulnerable to Denial of Service via Oversized JOSE Segments 1.3.1 1.6.5 -
Authlib CVE-2026-28490 HIGH Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle 1.3.1 - -
Authlib GHSA-m344-f55w-2m6j HIGH Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding 1.3.1 1.6.9 -
Authlib CVE-2026-28498 HIGH Authlib: Fail-Open Cryptographic Verification in OIDC Hash Binding 1.3.1 - -
Authlib CVE-2025-59420 HIGH Authlib: JWS/JWT accepts unknown crit headers (RFC violation → possible authz bypass) 1.3.1 - -
Authlib GHSA-9ggr-2464-2j32 HIGH Authlib: JWS/JWT accepts unknown crit headers (RFC violation → possible authz bypass) 1.3.1 1.6.4 -
Authlib CVE-2025-61920 HIGH Authlib is vulnerable to Denial of Service via Oversized JOSE Segments 1.3.1 - -
Authlib GHSA-7432-952r-cw78 HIGH Authlib Vulnerable to JWE RSA1_5 Bleichenbacher Padding Oracle 1.3.1 1.6.9 -
ℹ️ Other Vulnerabilities (11)
Package CVE Severity Summary Unsafe Version Fixed In Case
Authlib GHSA-jj8c-mmj3-mmgv MODERATE Authlib: Cross-site request forging when using cache 1.3.1 1.6.11 -
Authlib PYSEC-2026-25 MODERATE - 1.3.1 1.6.11 -
Authlib GHSA-g7f3-828f-7h7m MODERATE Authlib : JWE zip=DEF decompression bomb enables DoS 1.3.1 1.6.5 -
Authlib CVE-2025-62706 MODERATE Authlib : JWE zip=DEF decompression bomb enables DoS 1.3.1 - -
Authlib GHSA-w8p2-r796-3vmq MODERATE Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type 1.3.1 1.6.10 -
Authlib GHSA-fg6f-75jq-6523 MODERATE Authlib has 1-click Account Takeover vulnerability 1.3.1 1.6.6 -
Authlib CVE-2025-68158 MODERATE Authlib: 1-click Account Takeover 1.3.1 - -
Authlib PYSEC-2026-188 MODERATE - 1.3.1 1.6.12 -
Authlib GHSA-r95x-qfjj-fjj2 MODERATE Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect 1.3.1 1.7.1 -
pytest GHSA-6w46-j5rx-g56g MODERATE pytest has vulnerable tmpdir handling 7.1.2 9.0.3 -
pytest CVE-2025-71176 MODERATE - 7.1.2 - -

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

@dd-prapprover-prod-77c48c

dd-prapprover-prod-77c48c Bot commented Jul 7, 2026

Copy link
Copy Markdown

PRApprover will approve and merge this PR, FAQ, #dx-source-code-management

🛠️ PRApproval Status

  • ✅ PR is eligible for auto-approval by rule dependency-management-version-updater - 2026-07-07T12:46:19Z
  • ⬜ CI tests passed
  • ⬜ Approved
  • ⬜ Merge Started
  • ⬜ Merged

➡️ Current phase: waiting for CI tests to complete...

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants