aiohttp 3.14.1→3.14.3 (CVE-2026-69244 client C-parser OOB heap read — the reachable one, client-only usage via s3fs/gcsfs/aiobotocore; CVE-2026-59881/-69243 are server-side WS paths, no aiohttp server here) pyasn1 0.6.3→0.6.4 (CVE-2026-59884/-59885/-59886 quadratic-decode DoS — no direct untrusted ASN.1 decoding; transitive via google-auth/rsa) cryptography 49.0.0→50.0.0 (CVE-2026-69247 PKCS7 decrypt padding oracle — no EnvelopedData decryption paths; direct dep, pyproject floor raised) Per-issue exploitability rationale in tracker issues #581-#587. Full suite green with bumped packages installed: 14023 passed (serial proof run 26m45s at ecc3bae-era tree; parallel hook run 13m58s). pkg-manifest regenerated.
14 KiB
14 KiB