Skip to content

Bump idna 3.13 -> 3.17 to fix CVE-2026-45409 - #184

Merged
skearnes merged 1 commit into
mainfrom
bump-idna-3.17
Jun 10, 2026
Merged

skearnes merged 1 commit into
mainfrom
bump-idna-3.17

Conversation

@skearnes

Copy link
Copy Markdown
Member

Summary

Fixes Dependabot alert #65 (GHSA-65pc-fj4g-8rjx / CVE-2026-45409).

idna (a transitive runtime dependency pinned in uv.lock) has a medium-severity DoS: specially crafted inputs to idna.encode() (e.g. "٠" * N) bypass the incomplete CVE-2024-3651 fix and consume significant CPU for large N (CWE-1333). Patched in idna 3.15.

This bumps the transitive pin idna 3.13 -> 3.17 via uv lock --upgrade-package idna. Only uv.lock changes; no direct dependency or source code is affected.

🤖 Generated with Claude Code

Addresses Dependabot alert #65 (GHSA-65pc-fj4g-8rjx): a medium-severity
DoS in idna.encode() where specially crafted inputs bypass the
CVE-2024-3651 fix. Patched in idna 3.15; bumping the transitive pin in
uv.lock to 3.17.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@skearnes
skearnes requested a review from bdeadman May 30, 2026 16:35
@skearnes
skearnes merged commit 52ff89d into main Jun 10, 2026
15 checks passed
@skearnes
skearnes deleted the bump-idna-3.17 branch June 10, 2026 03:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants