Skip to content

fix(deps): vuln major: cffi, cryptography, pycparser [get_all_child_orgs/requirements.txt] - #218

Open
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/major/pip/get_all_child_orgs/5-1788763172
Open

fix(deps): vuln major: cffi, cryptography, pycparser [get_all_child_orgs/requirements.txt]#218
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/major/pip/get_all_child_orgs/5-1788763172

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown

Summary: High-severity security update — 3 packages upgraded (MAJOR changes included)

Manifests changed:

  • get_all_child_orgs/requirements.txt (pip)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
cryptography 1.8.1 50.0.1 major Direct 17 HIGH, 11 MEDIUM, 3 LOW
cffi 1.12.3 2.1.1 major Direct -
pycparser 2.19 3.0 major Direct -

Warning

Major Version Upgrade

This update includes major version changes that may contain breaking changes. Please:

  • Review the changelog/release notes for breaking changes
  • Test thoroughly in a staging environment
  • Update any code that depends on changed APIs
  • Ensure all tests pass before merging

Security Details

🚨 Critical & High Severity (17 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
cryptography GHSA-537c-gmf6-5ccf HIGH Vulnerable OpenSSL included in cryptography wheels 1.8.1 48.0.1 -
cryptography PYSEC-2026-1283 HIGH Python Cryptography package vulnerable to Bleichenbacher timing oracle attack 1.8.1 42.0.0 -
cryptography CVE-2023-0286 HIGH X.400 address type confusion in X.509 GeneralName 1.8.1 - -
cryptography PYSEC-2026-800 HIGH Vulnerable OpenSSL included in cryptography wheels 1.8.1 39.0.1 -
cryptography RUSTSEC-2023-0006 HIGH X.400 address type confusion in X.509 GeneralName 1.8.1 - -
cryptography GHSA-r6ph-v2qm-q3c2 HIGH cryptography Vulnerable to a Subgroup Attack Due to Missing Subgroup Validation for SECT Curves 1.8.1 46.0.5 -
cryptography CVE-2026-26007 HIGH cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves 1.8.1 - -
cryptography PYSEC-2026-2141 HIGH - 1.8.1 46.0.5 -
cryptography GHSA-jwv3-5hgf-82ww HIGH python-cryptography: Duplicate self-signed intermediates can cause exponential path-building 1.8.1 49.0.0 -
cryptography PYSEC-2021-62 HIGH - 1.8.1 3.2.1 -
cryptography CVE-2020-25659 HIGH - 1.8.1 - -
cryptography GHSA-hggm-jpg3-v476 HIGH RSA decryption vulnerable to Bleichenbacher timing vulnerability 1.8.1 3.2 -
cryptography CVE-2026-69249 high python-cryptography: Duplicate self-signed intermediates can cause exponential path-building 1.8.1 - -
cryptography GHSA-x4qr-2fvf-3mr5 HIGH Vulnerable OpenSSL included in cryptography wheels 1.8.1 39.0.1 -
cryptography CVE-2023-50782 HIGH Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659 1.8.1 - -
cryptography PYSEC-2026-3553 high python-cryptography: Duplicate self-signed intermediates can cause exponential path-building 1.8.1 49.0.0 -
cryptography GHSA-3ww4-gg4f-jr7f HIGH Python Cryptography package vulnerable to Bleichenbacher timing oracle attack 1.8.1 42.0.0 -
ℹ️ Other Vulnerabilities (14)
Package CVE Severity Summary Unsafe Version Fixed In Case
cryptography PYSEC-2026-35 medium - 1.8.1 46.0.6 -
cryptography CVE-2026-69248 medium python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees 1.8.1 - -
cryptography PYSEC-2026-3554 medium python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees 1.8.1 49.0.0 -
cryptography CVE-2024-0727 medium PKCS12 Decoding crashes 1.8.1 - -
cryptography PYSEC-2026-1285 medium Null pointer dereference in PKCS12 parsing 1.8.1 42.0.2 -
cryptography CVE-2026-34073 medium cryptography has incomplete DNS name constraint enforcement on peer names 1.8.1 - -
cryptography GHSA-9v9h-cgj8-h64p MODERATE Null pointer dereference in PKCS12 parsing 1.8.1 42.0.2 -
cryptography GHSA-w7pp-m8wf-vj6r MODERATE Cipher.update_into can corrupt memory if passed an immutable python object as the outbuf 1.8.1 39.0.1 -
cryptography PYSEC-2023-11 MODERATE - 1.8.1 94a50a9731f35405f0357fa5f3b177d46a726ab3 -
cryptography GHSA-m2h6-j472-rp4c MODERATE python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees 1.8.1 49.0.0 -
cryptography CVE-2023-23931 MODERATE Cipher.update_into can corrupt memory in pyca cryptography 1.8.1 - -
cryptography GHSA-jm77-qphf-c4w8 LOW pyca/cryptography's wheels include vulnerable OpenSSL 1.8.1 41.0.3 -
cryptography GHSA-m959-cc7f-wv43 LOW cryptography has incomplete DNS name constraint enforcement on peer names 1.8.1 46.0.6 -
cryptography GHSA-5cpq-8wj7-hf2v LOW Vulnerable OpenSSL included in cryptography wheels 1.8.1 41.0.0 -
⚠️ Dependencies that have Reached EOL (3)
Dependency Unsafe Version EOL Date New Version Path Case
cffi 1.12.3 - 2.1.1 get_all_child_orgs/requirements.txt -
cryptography 1.8.1 - 50.0.1 get_all_child_orgs/requirements.txt -
pycparser 2.19 - 3.0 get_all_child_orgs/requirements.txt -

Review Checklist

Extra review is recommended for this update:

  • Review changes for compatibility with your code
  • Check release notes for breaking changes
  • Run integration tests to verify service behavior
  • Test in staging environment before production
  • Monitor key metrics after deployment
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants