Skip to content

Security updates - #433

Open
github-actions[bot] wants to merge 1 commit into
masterfrom
security-updates
Open

github-actions[bot] wants to merge 1 commit into
masterfrom
security-updates

Conversation

@github-actions

@github-actions github-actions Bot commented Jul 10, 2026 •

Copy link
Copy Markdown
Contributor

Security Vulnerability Report

Generated on: 2026-10-07 05:03:22

Summary

Found vulnerabilities in 18 packages requiring updates.

Package Upgrades Overview

Package Current Version Recommended Version Vulnerabilities
aiohttp 3.14.1 3.14.3 6
anyio 4.9.0 4.14.2 2
click 8.2.1 8.3.3 1
fsspec 2025.5.1 2026.6.0 1
jupyter-server 2.20.0 2.21.0 1
jupyterlab 4.5.9 4.6.4 11
mistune 3.2.1 3.3.0 19
notebook 7.5.6 7.6.3 1
oauthlib 3.3.1 4.0.0 1
pillow 12.2.0 12.3.0 25
pyasn1 0.6.3 0.6.4 6
pymdown-extensions 10.21.3 11.0.1 4
pymongo 4.13.2 4.18.2 4
setuptools 80.10.2 83.0.0 2
soupsieve 2.7 2.9.0 6
tornado 6.5.7 6.5.9 6
urllib3 2.7.0 2.8.0 3
virtualenv 20.36.1 21.7.13 8

Detailed Vulnerability Information

aiohttp (v3.14.1)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-3547 3.14.2 GHSA-mq44-7p77-q5h7, CVE-2026-59881
PYSEC-2026-3546 3.14.2 CVE-2026-69243, GHSA-mfx4-hv73-q22v
PYSEC-2026-3545 3.14.3 GHSA-cq5v-8q36-5273, CVE-2026-69244
PYSEC-2026-3545 3.14.3 GHSA-cq5v-8q36-5273, CVE-2026-69244
PYSEC-2026-3546 3.14.2 CVE-2026-69243, GHSA-mfx4-hv73-q22v
PYSEC-2026-3547 3.14.2 GHSA-mq44-7p77-q5h7, CVE-2026-59881

anyio (v4.9.0)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-4025 4.14.2 GHSA-82r6-8w77-94w6, CVE-2026-63374
PYSEC-2026-4024 4.14.2 GHSA-5p39-cfhj-2xmp, CVE-2026-64847

click (v8.2.1)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-2132 8.3.3 GHSA-47fr-3ffg-hgmw, CVE-2026-7246

fsspec (v2025.5.1)

Vulnerability ID Fix Versions Aliases
CVE-2026-104851 2026.6.0 GHSA-27vj-qcqg-25rc

jupyter-server (v2.20.0)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-4054 2.21.0 GHSA-c3mw-737p-c7g2, CVE-2026-86049

jupyterlab (v4.5.9)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-3671 4.5.10, 4.6.2 BIT-jupyterlab-2026-73415, GHSA-gx64-gj6p-pc4c, CVE-2026-73415
PYSEC-2026-3672 4.5.10, 4.6.2 GHSA-pppj-hq3g-57pj, CVE-2026-73417, BIT-jupyterlab-2026-73417
PYSEC-2026-3670 4.5.10, 4.6.2 BIT-jupyterlab-2026-73416, GHSA-89vp-jrxv-24w8, CVE-2026-73416
PYSEC-2026-4055 4.5.11, 4.6.4 CVE-2026-102904, GHSA-3325-v43h-43rv
PYSEC-2026-3672 4.5.10, 4.6.2 CVE-2026-73417, GHSA-pppj-hq3g-57pj
PYSEC-2026-3670 4.5.10, 4.6.2 CVE-2026-73416, GHSA-89vp-jrxv-24w8
PYSEC-2026-3671 4.5.10, 4.6.2 GHSA-gx64-gj6p-pc4c, CVE-2026-73415
PYSEC-2026-4056 4.5.11, 4.6.4 GHSA-3jqq-pw4j-pqcj, CVE-2026-102830
PYSEC-2026-4057 4.5.11, 4.6.4 GHSA-6966-vjj6-99xv, CVE-2026-102831
GHSA-h5v5-8746-g7mm 4.5.10, 4.6.2
CVE-2026-73626 4.5.10, 4.6.2 GHSA-whvh-wf3x-g77j

mistune (v3.2.1)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-2652 3.3.0 GHSA-qcq2-496w-v96p, CVE-2026-49851
PYSEC-2026-2217 3.3.0 GHSA-qfrw-5rxm-mhh2, CVE-2026-59929
PYSEC-2026-2214 3.3.0 GHSA-g97x-gvcm-x72h, CVE-2026-59926
PYSEC-2026-2215 3.3.0 GHSA-8mpj-m6qm-5qr8, CVE-2026-59927
PYSEC-2026-2212 3.3.0 CVE-2026-59924, GHSA-r4rv-85jg-w4mf
PYSEC-2026-2216 3.3.0 GHSA-ffq3-xpv3-j92q, CVE-2026-59928
PYSEC-2026-2213 3.3.0 GHSA-4j32-57v6-6g45, CVE-2026-59925
PYSEC-2026-2218 3.3.0 CVE-2026-59930, GHSA-2hm2-hc3v-44h9
PYSEC-2026-2211 3.3.0 CVE-2026-59923, GHSA-8c25-4j27-2rv3
PYSEC-2026-2210 3.3.0 CVE-2026-59922, GHSA-c8j7-8cv4-2xmq
PYSEC-2026-2652 3.3.0 GHSA-qcq2-496w-v96p, CVE-2026-49851
PYSEC-2026-2216 3.3.0 GHSA-ffq3-xpv3-j92q, CVE-2026-59928
PYSEC-2026-2215 3.3.0 GHSA-8mpj-m6qm-5qr8, CVE-2026-59927
PYSEC-2026-2210 3.3.0 CVE-2026-59922, GHSA-c8j7-8cv4-2xmq
PYSEC-2026-2214 3.3.0 GHSA-g97x-gvcm-x72h, CVE-2026-59926
PYSEC-2026-2217 3.3.0 GHSA-qfrw-5rxm-mhh2, CVE-2026-59929
PYSEC-2026-2218 3.3.0 CVE-2026-59930, GHSA-2hm2-hc3v-44h9
PYSEC-2026-2213 3.3.0 GHSA-4j32-57v6-6g45, CVE-2026-59925
PYSEC-2026-2211 3.3.0 CVE-2026-59923, GHSA-8c25-4j27-2rv3

notebook (v7.5.6)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-4112 7.6.3 GHSA-6966-vjj6-99xv, PYSEC-2026-4058, PYSEC-2026-4057, CVE-2026-102831, PYSEC-2026-4060

oauthlib (v3.3.1)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-4114 4.0.0 GHSA-xpv3-w29h-x7cv, CVE-2026-49265

pillow (v12.2.0)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-2253 12.3.0 GHSA-8v84-f9pq-wr9x, CVE-2026-54059, BIT-pillow-2026-54059
PYSEC-2026-2255 12.3.0 CVE-2026-55379, BIT-pillow-2026-55379, GHSA-45hq-cxwh-f6vc
PYSEC-2026-2257 12.3.0 GHSA-4x4j-2g7c-83w6, CVE-2026-55798
PYSEC-2026-2256 12.3.0 GHSA-phj9-mv4w-65pm, BIT-pillow-2026-55380, CVE-2026-55380
PYSEC-2026-2254 12.3.0 CVE-2026-54060, GHSA-5x94-69rx-g8h2, BIT-pillow-2026-54060
PYSEC-2026-3453 12.3.0 GHSA-9hw9-ch79-4vh6, CVE-2026-59205, BIT-pillow-2026-59205
PYSEC-2026-3451 12.3.0 BIT-pillow-2026-59199, GHSA-6r8x-57c9-28j4, CVE-2026-59199
PYSEC-2026-3452 12.3.0 BIT-pillow-2026-59203, GHSA-pg7v-jwj7-p798, CVE-2026-59203
PYSEC-2026-3493 12.3.0 CVE-2026-54058, GHSA-62p4-gmf7-7g93, BIT-pillow-2026-54058
PYSEC-2026-2254 12.3.0 CVE-2026-54060, BIT-pillow-2026-54060, GHSA-5x94-69rx-g8h2
PYSEC-2026-2253 12.3.0 CVE-2026-54059, GHSA-8v84-f9pq-wr9x, BIT-pillow-2026-54059
PYSEC-2026-2256 12.3.0 GHSA-phj9-mv4w-65pm, BIT-pillow-2026-55380, CVE-2026-55380
PYSEC-2026-2255 12.3.0 CVE-2026-55379, BIT-pillow-2026-55379, GHSA-45hq-cxwh-f6vc
PYSEC-2026-3454 12.3.0 CVE-2026-59197, GHSA-xj96-63gp-2gmr, BIT-pillow-2026-59197
PYSEC-2026-3451 12.3.0 BIT-pillow-2026-59199, GHSA-6r8x-57c9-28j4, CVE-2026-59199
PYSEC-2026-3494 12.3.0 BIT-pillow-2026-59198, GHSA-fj7v-r99m-22gq, CVE-2026-59198
PYSEC-2026-3452 12.3.0 BIT-pillow-2026-59203, GHSA-pg7v-jwj7-p798, CVE-2026-59203
PYSEC-2026-3495 12.3.0 BIT-pillow-2026-59200, CVE-2026-59200, GHSA-jjj6-mw9f-p565
PYSEC-2026-3496 12.3.0 CVE-2026-59204, BIT-pillow-2026-59204, GHSA-vjc4-5qp5-m44j
PYSEC-2026-3453 12.3.0 CVE-2026-59205, GHSA-9hw9-ch79-4vh6, BIT-pillow-2026-59205
PYSEC-2026-3454 12.3.0 GHSA-xj96-63gp-2gmr, CVE-2026-59197
PYSEC-2026-3495 12.3.0 CVE-2026-59200, GHSA-jjj6-mw9f-p565
PYSEC-2026-3496 12.3.0 CVE-2026-59204, GHSA-vjc4-5qp5-m44j
PYSEC-2026-3494 12.3.0 GHSA-fj7v-r99m-22gq, CVE-2026-59198
PYSEC-2026-3493 12.3.0 CVE-2026-54058, GHSA-62p4-gmf7-7g93

pyasn1 (v0.6.3)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-3456 0.6.4 CVE-2026-59885, GHSA-8ppf-4f7h-5ppj
PYSEC-2026-3457 0.6.4 CVE-2026-59886, GHSA-hm4w-wwcw-mr6r
PYSEC-2026-3456 0.6.4 CVE-2026-59885, GHSA-8ppf-4f7h-5ppj
PYSEC-2026-3457 0.6.4 CVE-2026-59886, GHSA-hm4w-wwcw-mr6r
PYSEC-2026-3455 0.6.4 GHSA-m4p7-r5rc-7g4j, CVE-2026-59884
PYSEC-2026-3455 0.6.4 GHSA-m4p7-r5rc-7g4j, CVE-2026-59884

pymdown-extensions (v10.21.3)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-3609 11.0.0 GHSA-9xwg-3r6f-jcx2, CVE-2026-61632
PYSEC-2026-3609 11.0.0 GHSA-9xwg-3r6f-jcx2, CVE-2026-61632
PYSEC-2026-3654 11.0.1 GHSA-gm37-52c6-37mw, CVE-2026-67422
PYSEC-2026-3654 11.0.1 GHSA-gm37-52c6-37mw, CVE-2026-67422

pymongo (v4.13.2)

Vulnerability ID Fix Versions Aliases
CVE-2026-88029 4.18.1 GHSA-8fvv-fgr5-f8ch
CVE-2026-96747 4.18.2 GHSA-qx36-8mw2-4r3x
CVE-2026-96749 4.18.2 GHSA-v4x9-3549-crwv
CVE-2026-96748 4.18.2 GHSA-vp6j-j7w5-5xjj

setuptools (v80.10.2)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-3447 83.0.0 BIT-setuptools-2026-59890, CVE-2026-59890, GHSA-h35f-9h28-mq5c
PYSEC-2026-3447 83.0.0 BIT-setuptools-2026-59890, CVE-2026-59890, GHSA-h35f-9h28-mq5c

soupsieve (v2.7)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-3072 2.8.4 GHSA-836r-79rf-4m37, CVE-2026-49477
PYSEC-2026-3071 2.8.4 GHSA-2wc2-fm75-p42x, CVE-2026-49476
PYSEC-2026-3072 2.8.4 GHSA-836r-79rf-4m37, CVE-2026-49477
PYSEC-2026-3071 2.8.4 GHSA-2wc2-fm75-p42x, CVE-2026-49476
PYSEC-2026-4170 2.9.0 GHSA-gjv8-xp57-g29c, CVE-2026-86000
PYSEC-2026-4171 2.9.0 GHSA-j934-xhv5-fg8f, CVE-2026-85999

tornado (v6.5.7)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-3928 6.5.8 GHSA-mpf4-983q-p7j4, CVE-2026-82397
GHSA-chx6-46f5-w4vp 6.5.9
GHSA-c2m8-h5v5-343r 6.5.9
GHSA-3hv7-mjh2-fv65 6.5.9
GHSA-wwv5-g3v4-889x 6.5.8
GHSA-8423-8fgw-73vq 6.5.8

urllib3 (v2.7.0)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-4177 2.8.0 GHSA-vxq7-64xx-v4gw, CVE-2026-97689
PYSEC-2026-4176 2.8.0 CVE-2026-97688, GHSA-gh4c-6fx4-qh6g
PYSEC-2026-4175 2.8.0 GHSA-8988-9cw3-xx77, CVE-2026-97687

virtualenv (v20.36.1)

Vulnerability ID Fix Versions Aliases
PYSEC-2026-4011 21.7.12 CVE-2026-102930, GHSA-94p9-xgh2-xp45
PYSEC-2026-4012 21.7.11 CVE-2026-102938, GHSA-9h9j-4vrj-gf7g
PYSEC-2026-4014 21.7.12 GHSA-x78j-v8h9-3j2q, CVE-2026-102937
PYSEC-2026-4013 21.7.13 CVE-2026-102925, GHSA-p58f-9548-mpm2
PYSEC-2026-4011 21.7.12 CVE-2026-102930, GHSA-94p9-xgh2-xp45
PYSEC-2026-4012 21.7.11 CVE-2026-102938, GHSA-9h9j-4vrj-gf7g
PYSEC-2026-4013 21.7.13 CVE-2026-102925, GHSA-p58f-9548-mpm2
PYSEC-2026-4014 21.7.12 GHSA-x78j-v8h9-3j2q, CVE-2026-102937

Recommended Actions

  1. Review the vulnerability details above.
  2. Close and reopen this PR to trigger CI/CD tests.
  3. Approve and merge the PR if everything looks good.

This report was generated automatically. Please verify all upgrades before applying.

@github-actions
github-actions Bot force-pushed the security-updates branch 2 times, most recently from 7847bfa to b83d223 Compare July 15, 2026 02:43
@github-actions
github-actions Bot force-pushed the security-updates branch 3 times, most recently from dc5ae59 to 7fb2bb9 Compare July 23, 2026 03:14
@github-actions
github-actions Bot force-pushed the security-updates branch 3 times, most recently from 0cd0474 to 9a7c10e Compare August 8, 2026 01:50
@github-actions
github-actions Bot force-pushed the security-updates branch 2 times, most recently from 3173b75 to 3904620 Compare September 5, 2026 03:38
@github-actions
github-actions Bot force-pushed the security-updates branch 2 times, most recently from 22a49df to 470c1b9 Compare September 12, 2026 03:48
@github-actions
github-actions Bot force-pushed the security-updates branch 3 times, most recently from b1f7a44 to 4540dd0 Compare September 24, 2026 03:51
@github-actions
github-actions Bot force-pushed the security-updates branch 4 times, most recently from 801d06a to 4a67ddf Compare October 6, 2026 05:33

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants