Skip to content

fix(deps): Bump pyasn1 to 0.6.4 to address three DoS advisories - #140

Merged
akalex merged 1 commit into
masterfrom
bugfix/dependabot-pyasn1-cve
Aug 2, 2026
Merged

akalex merged 1 commit into
masterfrom
bugfix/dependabot-pyasn1-cve

Conversation

@akalex

@akalex akalex commented Aug 2, 2026

Copy link
Copy Markdown
Member

Resolves Dependabot alerts #36, #37, #38 (all high severity), fixed in pyasn1 0.6.4:

pyasn1 is a transitive dependency via google-auth, so only poetry.lock changes. Release 6.2.1.

Resolves Dependabot alerts #36, #37, #38 (all high severity), fixed in
pyasn1 0.6.4:

- GHSA-m4p7-r5rc-7g4j: BER/CER/DER decoder DoS via unbounded long-form tag IDs
- GHSA-8ppf-4f7h-5ppj: quadratic complexity in OBJECT IDENTIFIER and
  RELATIVE-OID processing
- GHSA-hm4w-wwcw-mr6r: uncontrolled resource consumption when converting
  decoded REAL values

pyasn1 is a transitive dependency via google-auth, so only poetry.lock
changes. Release 6.2.1.
@akalex
akalex merged commit 4633f96 into master Aug 2, 2026
15 checks passed
@akalex
akalex deleted the bugfix/dependabot-pyasn1-cve branch August 2, 2026 10:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant