mirror of
https://github.com/OpenHands/OpenHands.git
synced 2026-10-07 16:38:34 +08:00
fix: Fix CVE-2026-44681: Update authlib to >=1.6.12 (#14983)
Co-authored-by: OpenHands CVE Fix Bot <openhands@all-hands.dev> Co-authored-by: aivong-openhands <ai.vong@openhands.dev>
This commit is contained in:
co-authored by
OpenHands CVE Fix Bot
aivong-openhands
parent
77bd80d3a4
commit
e6fe5057fc
Generated
+7
-7
@@ -544,14 +544,14 @@ files = [
|
||||
|
||||
[[package]]
|
||||
name = "authlib"
|
||||
version = "1.6.9"
|
||||
version = "1.6.12"
|
||||
description = "The ultimate Python library in building OAuth and OpenID Connect servers and clients."
|
||||
optional = false
|
||||
python-versions = ">=3.9"
|
||||
groups = ["main"]
|
||||
files = [
|
||||
{file = "authlib-1.6.9-py2.py3-none-any.whl", hash = "sha256:f08b4c14e08f0861dc18a32357b33fbcfd2ea86cfe3fe149484b4d764c4a0ac3"},
|
||||
{file = "authlib-1.6.9.tar.gz", hash = "sha256:d8f2421e7e5980cc1ddb4e32d3f5fa659cfaf60d8eaf3281ebed192e4ab74f04"},
|
||||
{file = "authlib-1.6.12-py2.py3-none-any.whl", hash = "sha256:e9229ad7fde610b139dd12f5edbe97eab9ee78bfb85691247e767727850b99ab"},
|
||||
{file = "authlib-1.6.12.tar.gz", hash = "sha256:0656d8482f28fc8221929d5f35b2bde5d13e10555ebc06b4561b0d622e83b1bd"},
|
||||
]
|
||||
|
||||
[package.dependencies]
|
||||
@@ -5814,7 +5814,7 @@ aiohttp = ">=3.14.1"
|
||||
anthropic = {version = "*", extras = ["vertex"]}
|
||||
anyio = "4.9"
|
||||
asyncpg = ">=0.30"
|
||||
authlib = ">=1.6.9"
|
||||
authlib = ">=1.6.12"
|
||||
bashlex = ">=0.18"
|
||||
binaryornot = ">=0.5.0,<1"
|
||||
boto3 = "*"
|
||||
@@ -5866,7 +5866,7 @@ pybase62 = ">=1"
|
||||
pygithub = ">=2.5"
|
||||
pyjwt = ">=2.13.0"
|
||||
pylatexenc = "*"
|
||||
pypdf = ">=6.10.2"
|
||||
pypdf = ">=6.13.3"
|
||||
python-docx = "*"
|
||||
python-dotenv = "*"
|
||||
python-frontmatter = ">=1.1"
|
||||
@@ -5884,7 +5884,7 @@ setuptools = ">=78.1.1"
|
||||
shellingham = ">=1.5.4"
|
||||
sqlalchemy = {version = ">=2.0.40", extras = ["asyncio"]}
|
||||
sse-starlette = ">=3.0.2"
|
||||
starlette = ">=0.49.1"
|
||||
starlette = ">=1.3.1"
|
||||
tenacity = ">=8.5,<10"
|
||||
termcolor = "*"
|
||||
toml = "*"
|
||||
@@ -14458,4 +14458,4 @@ cffi = ["cffi (>=1.17,<2.0) ; platform_python_implementation != \"PyPy\" and pyt
|
||||
[metadata]
|
||||
lock-version = "2.1"
|
||||
python-versions = "^3.12,<3.14"
|
||||
content-hash = "55a09a40217bbbc876e5864b78c941d86a261e4111bce7e4495c1dd75df43fd7"
|
||||
content-hash = "3ed1ff54e78b57ec90cadf57dd1165ef76945c01c87ae358c6a8f3da1fd1e5a8"
|
||||
|
||||
@@ -22,6 +22,7 @@ packages = [
|
||||
[tool.poetry.dependencies]
|
||||
python = "^3.12,<3.14"
|
||||
openhands-ai = { path = "../", develop = true }
|
||||
authlib = ">=1.6.12,<1.7"
|
||||
gspread = "^6.1.4"
|
||||
alembic = "^1.14.1"
|
||||
cloud-sql-python-connector = "^1.16.0"
|
||||
|
||||
Generated
+1
-1
@@ -13762,4 +13762,4 @@ cffi = ["cffi (>=1.17,<2.0) ; platform_python_implementation != \"PyPy\" and pyt
|
||||
[metadata]
|
||||
lock-version = "2.1"
|
||||
python-versions = "^3.12,<3.14"
|
||||
content-hash = "833c65cccd3e915a2fb05abbc0d7c15503f1ba0730d1600f0f9f7259b5ce4200"
|
||||
content-hash = "d3e4046361c4dfef83ab27d9492ae39f4daea1392335da0e50d36be01a2808b3"
|
||||
|
||||
+2
-2
@@ -25,7 +25,7 @@ dependencies = [
|
||||
"anthropic[vertex]",
|
||||
"anyio==4.9",
|
||||
"asyncpg>=0.30",
|
||||
"authlib>=1.6.9",
|
||||
"authlib>=1.6.12,!=1.7.0",
|
||||
"bashlex>=0.18",
|
||||
"binaryornot>=0.5.0,<1",
|
||||
"boto3",
|
||||
@@ -158,7 +158,7 @@ include = [
|
||||
|
||||
[tool.poetry.dependencies]
|
||||
python = "^3.12,<3.14"
|
||||
authlib = ">=1.6.9" # CVE-2026-27962 (fixed in 1.6.9)
|
||||
authlib = ">=1.6.12,!=1.7.0" # CVE-2026-44681 (fixed in 1.6.12 and 1.7.1; 1.7.0 is vulnerable)
|
||||
orjson = ">=3.11.6" # Pinned to fix CVE-2025-67221
|
||||
litellm = "1.84.1" # Exact pin to the verified 1.84.1 release; bump explicitly when upgrading (rather than a floor) to ensure only the tested version is used
|
||||
openai = "2.33.0" # Pin because litellm 1.84.1 requires 2.33.0 and is incompatible with >=1.100.0 (BerriAI/litellm#13711)
|
||||
|
||||
@@ -329,15 +329,15 @@ wheels = [
|
||||
|
||||
[[package]]
|
||||
name = "authlib"
|
||||
version = "1.7.0"
|
||||
version = "1.7.2"
|
||||
source = { registry = "https://pypi.org/simple" }
|
||||
dependencies = [
|
||||
{ name = "cryptography" },
|
||||
{ name = "joserfc" },
|
||||
]
|
||||
sdist = { url = "https://files.pythonhosted.org/packages/d9/82/4d0603f30c1b4629b1f091bb266b0d7986434891d6940a8c87f8098db24e/authlib-1.7.0.tar.gz", hash = "sha256:b3e326c9aa9cc3ea95fe7d89fd880722d3608da4d00e8a27e061e64b48d801d5", size = 175890, upload-time = "2026-04-18T11:00:28.559Z" }
|
||||
sdist = { url = "https://files.pythonhosted.org/packages/36/98/7d93f30d029643c0275dbc0bd6d5a6f670661ee6c9a94d93af7ab4887600/authlib-1.7.2.tar.gz", hash = "sha256:2cea25fefcd4e7173bdf1372c0afc265c8034b23a8cd5dcb6a9164b826c64231", size = 176511, upload-time = "2026-05-06T08:10:23.116Z" }
|
||||
wheels = [
|
||||
{ url = "https://files.pythonhosted.org/packages/ca/48/c954218b2a250e23f178f10167c4173fecb5a75d2c206f0a67ba58006c26/authlib-1.7.0-py2.py3-none-any.whl", hash = "sha256:e36817afb02f6f0b6bf55f150782499ddd6ddf44b402bb055d3263cc65ac9ae0", size = 258779, upload-time = "2026-04-18T11:00:26.64Z" },
|
||||
{ url = "https://files.pythonhosted.org/packages/fb/95/adcb68e20c34162e9135f370d6e31737719c2b6f94bc953fe7ed1f10fe21/authlib-1.7.2-py2.py3-none-any.whl", hash = "sha256:3e1faedc9d87e7d56a164eca3ccb6ace0d61b94abe83e92242f8dc8bba9b4a9f", size = 259548, upload-time = "2026-05-06T08:10:21.436Z" },
|
||||
]
|
||||
|
||||
[[package]]
|
||||
@@ -3323,7 +3323,7 @@ requires-dist = [
|
||||
{ name = "anthropic", extras = ["vertex"] },
|
||||
{ name = "anyio", specifier = "==4.9" },
|
||||
{ name = "asyncpg", specifier = ">=0.30" },
|
||||
{ name = "authlib", specifier = ">=1.6.9" },
|
||||
{ name = "authlib", specifier = ">=1.6.12,!=1.7.0" },
|
||||
{ name = "bashlex", specifier = ">=0.18" },
|
||||
{ name = "binaryornot", specifier = ">=0.5.0,<1" },
|
||||
{ name = "boto3" },
|
||||
|
||||
Reference in New Issue
Block a user