Skip to content

[Snyk] Security upgrade cryptography from 3.2.1 to 46.0.5 - #112

Open
Jsn2win wants to merge 1 commit into
mainfrom
snyk-fix-0b8d25f17fabef487cc2ba66e414176d
Open

Jsn2win wants to merge 1 commit into
mainfrom
snyk-fix-0b8d25f17fabef487cc2ba66e414176d

fix: requirements.txt to reduce vulnerabilities

d5ce684
Select commit
Loading
Failed to load commit list.
Mend Bolt for GitHub / WhiteSource Security Check failed Feb 16, 2026 in 5m 11s

Security Report

You have successfully remediated 51 vulnerabilities, but introduced 7 new vulnerabilities in this branch.

❌ New vulnerabilities:

Vulnerability Severity CVSS Score Vulnerable Library Direct Library Suggested Fix Issue
CVE-2021-41945

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260216130708_FRHTZF/python_VWYLXG/20260216130710/20/httpx-0.16.1-py3-none-any.whl

Dependency Hierarchy:

-> ❌ httpx-0.16.1-py3-none-any.whl (Vulnerable Library)

Critical 9.1 Direct httpx-0.16.1-py3-none-any.whl httpx-0.16.1-py3-none-any.whl httpx - 0.23.0 #35
CVE-2026-24486

Path to dependency file: /tmp/ws-scm/JsMERG

Path to vulnerable library: /tmp/ws-ua_20260216130708_FRHTZF/python_VWYLXG/202602161309451/env/lib/python3.9/site-packages/python_multipart-0.0.20.dist-info,/tmp/ws-ua_20260216130708_FRHTZF/python_VWYLXG/202602161309451/env/lib/python3.9/site-packages/python_multipart-0.0.20.dist-info

Dependency Hierarchy:

-> ❌ python_multipart-0.0.20-py3-none-any.whl (Vulnerable Library)

High 8.6 Direct python_multipart-0.0.20-py3-none-any.whl python_multipart-0.0.20-py3-none-any.whl python-multipart - 0.0.22,https://github.com/Kludex/python-multipart.git - 0.0.22 None
CVE-2021-32677

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260216130708_FRHTZF/python_VWYLXG/20260216130710/11/fastapi-0.61.1-py3-none-any.whl

Dependency Hierarchy:

-> ❌ fastapi-0.61.1-py3-none-any.whl (Vulnerable Library)

High 8.2 Direct fastapi-0.61.1-py3-none-any.whl fastapi-0.61.1-py3-none-any.whl 0.65.2 None
CVE-2024-6827

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260216130708_FRHTZF/python_VWYLXG/20260216130710/12/gunicorn-20.0.4-py2.py3-none-any.whl

Dependency Hierarchy:

-> ❌ gunicorn-20.0.4-py2.py3-none-any.whl (Vulnerable Library)

High 7.5 Direct gunicorn-20.0.4-py2.py3-none-any.whl gunicorn-20.0.4-py2.py3-none-any.whl 23.0.0 None
CVE-2024-1135

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260216130708_FRHTZF/python_VWYLXG/20260216130710/12/gunicorn-20.0.4-py2.py3-none-any.whl

Dependency Hierarchy:

-> ❌ gunicorn-20.0.4-py2.py3-none-any.whl (Vulnerable Library)

High 7.5 Direct gunicorn-20.0.4-py2.py3-none-any.whl gunicorn-20.0.4-py2.py3-none-any.whl gunicorn - 22.0.0 #84
CVE-2021-33880

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260216130708_FRHTZF/python_VWYLXG/20260216130710/48/websockets-8.1.tar.gz

Dependency Hierarchy:

-> ❌ websockets-8.1.tar.gz (Vulnerable Library)

Medium 5.9 Direct websockets-8.1.tar.gz websockets-8.1.tar.gz 9.1 #13
CVE-2021-29510

Path to dependency file: /requirements.txt

Path to vulnerable library: /tmp/ws-ua_20260216130708_FRHTZF/python_VWYLXG/20260216130710/27/pydantic-1.6.1-py36.py37.py38-none-any.whl

Dependency Hierarchy:

-> ❌ pydantic-1.6.1-py36.py37.py38-none-any.whl (Vulnerable Library)

Low 3.3 Direct pydantic-1.6.1-py36.py37.py38-none-any.whl pydantic-1.6.1-py36.py37.py38-none-any.whl 1.6.2 #8

✔️ Remediated vulnerabilities:

Vulnerability Vulnerable Library
CVE-2024-6827 gunicorn-20.1.0-py3-none-any.whl
CVE-2023-37920 certifi-2020.12.5-py2.py3-none-any.whl
CVE-2023-4807 cryptography-3.4.7-cp36-abi3-manylinux2014_x86_64.whl
CVE-2021-33503 urllib3-1.26.4-py2.py3-none-any.whl
CVE-2024-56326 Jinja2-2.11.3-py2.py3-none-any.whl
CVE-2022-29217 PyJWT-2.1.0-py3-none-any.whl
CVE-2025-43859 h11-0.12.0-py3-none-any.whl
CVE-2023-43804 urllib3-1.26.4-py2.py3-none-any.whl
CVE-2023-28117 sentry_sdk-1.1.0-py2.py3-none-any.whl
CVE-2023-50782 cryptography-3.4.7-cp36-abi3-manylinux2014_x86_64.whl
CVE-2024-0727 cryptography-3.2.1-cp35-abi3-manylinux2010_x86_64.whl
CVE-2024-0727 cryptography-3.4.7-cp36-abi3-manylinux2014_x86_64.whl
CVE-2021-33880 websockets-8.1-cp37-cp37m-manylinux2010_x86_64.whl
CVE-2023-0286 cryptography-3.2.1-cp35-abi3-manylinux2010_x86_64.whl
CVE-2023-4807 cryptography-3.2.1-cp35-abi3-manylinux2010_x86_64.whl
CVE-2023-45803 urllib3-1.26.4-py2.py3-none-any.whl
CVE-2025-66418 urllib3-1.26.4-py2.py3-none-any.whl
CVE-2022-23491 certifi-2020.12.5-py2.py3-none-any.whl
CVE-2020-36242 cryptography-3.2.1-cp35-abi3-manylinux2010_x86_64.whl
CVE-2024-47081 requests-2.25.1-py2.py3-none-any.whl
CVE-2023-3446 cryptography-3.2.1-cp35-abi3-manylinux2010_x86_64.whl
CVE-2024-6345 setuptools-56.1.0-py3-none-any.whl
CVE-2023-3446 cryptography-3.4.7-cp36-abi3-manylinux2014_x86_64.whl
CVE-2023-32681 requests-2.25.1-py2.py3-none-any.whl
CVE-2021-41945 httpx-0.18.1-py3-none-any.whl
CVE-2023-0286 cryptography-3.4.7-cp36-abi3-manylinux2014_x86_64.whl
CVE-2024-37891 urllib3-1.26.4-py2.py3-none-any.whl
CVE-2025-66471 urllib3-1.26.4-py2.py3-none-any.whl
CVE-2024-40647 sentry_sdk-1.1.0-py2.py3-none-any.whl
CVE-2023-38325 cryptography-3.2.1-cp35-abi3-manylinux2010_x86_64.whl
CVE-2022-40897 setuptools-56.1.0-py3-none-any.whl
CVE-2023-49083 cryptography-3.2.1-cp35-abi3-manylinux2010_x86_64.whl
CVE-2025-47273 setuptools-56.1.0-py3-none-any.whl
CVE-2023-49083 cryptography-3.4.7-cp36-abi3-manylinux2014_x86_64.whl
CVE-2023-2650 cryptography-3.2.1-cp35-abi3-manylinux2010_x86_64.whl
CVE-2025-50181 urllib3-1.26.4-py2.py3-none-any.whl
CVE-2023-38325 cryptography-3.4.7-cp36-abi3-manylinux2014_x86_64.whl
CVE-2023-23931 cryptography-3.4.7-cp36-abi3-manylinux2014_x86_64.whl
CVE-2023-50782 cryptography-3.2.1-cp35-abi3-manylinux2010_x86_64.whl
CVE-2023-2650 cryptography-3.4.7-cp36-abi3-manylinux2014_x86_64.whl
CVE-2024-22195 Jinja2-2.11.3-py2.py3-none-any.whl
CVE-2024-56201 Jinja2-2.11.3-py2.py3-none-any.whl
CVE-2021-29510 pydantic-1.8.1-cp37-cp37m-manylinux2014_x86_64.whl
CVE-2026-26007 cryptography-3.4.7-cp36-abi3-manylinux2014_x86_64.whl
CVE-2024-34064 Jinja2-2.11.3-py2.py3-none-any.whl
CVE-2026-26007 cryptography-3.2.1-cp35-abi3-manylinux2010_x86_64.whl
CVE-2026-21441 urllib3-1.26.4-py2.py3-none-any.whl
CVE-2024-1135 gunicorn-20.1.0-py3-none-any.whl
CVE-2024-35195 requests-2.25.1-py2.py3-none-any.whl
CVE-2025-27516 Jinja2-2.11.3-py2.py3-none-any.whl
CVE-2023-23931 cryptography-3.2.1-cp35-abi3-manylinux2010_x86_64.whl

Base branch total remaining vulnerabilities: 96
Base branch commit: null


Total libraries scanned: 110

Scan token: 5e74315e066d4983a76b78201375cdb0