Skip to content

Updated cryptography from 46.0.3 to 46.0.5 and pip from 25.3 to 26.0.1.#16

Merged
redcatbear merged 1 commit intomainfrom
security/fix_CVE-2026-26007
Mar 3, 2026
Merged

Updated cryptography from 46.0.3 to 46.0.5 and pip from 25.3 to 26.0.1.#16
redcatbear merged 1 commit intomainfrom
security/fix_CVE-2026-26007

Conversation

@redcatbear
Copy link
Collaborator

@redcatbear redcatbear commented Mar 2, 2026

Updated cryptography from 46.0.3 to 46.0.5 (CVE-2026-26007):

An attacker could create a malicious public key that reveals portions of your
private key when using certain uncommon elliptic curves (binary curves).

Also updated pip from 25.3 to 26.0.1.

Fixed a directory traversal vulnerability.

@redcatbear redcatbear self-assigned this Mar 2, 2026
@redcatbear redcatbear added the refactoring Code improvement without behavior change label Mar 2, 2026
@redcatbear redcatbear temporarily deployed to manual-approval March 2, 2026 13:54 — with GitHub Actions Inactive
@sonarqubecloud
Copy link

sonarqubecloud bot commented Mar 2, 2026

@redcatbear redcatbear merged commit a2ca67e into main Mar 3, 2026
21 checks passed
@kratz00 kratz00 deleted the security/fix_CVE-2026-26007 branch March 3, 2026 07:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

refactoring Code improvement without behavior change

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants