Skip to content

chore(deps): Bump the minor-and-patch group across 1 directory with 18 updates - #804

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/a2a/weather_service/minor-and-patch-8edf2de4f2
Open

chore(deps): Bump the minor-and-patch group across 1 directory with 18 updates#804
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/a2a/weather_service/minor-and-patch-8edf2de4f2

chore(deps): Bump the minor-and-patch group across 1 directory with 1…

2333369
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / Trivy failed Aug 14, 2026 in 7s

25 new alerts including 14 high severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 14 high
  • 10 medium
  • 1 low

Alerts not introduced by this pull request might have been detected because the code changes were too large.

See annotations below for details.

View all branch alerts.

Annotations

Check failure on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

Pillow: Pillow: Denial of Service via crafted JPEG2000 image High

Package: pillow
Installed Version: 12.2.0
Vulnerability CVE-2026-59204
Severity: HIGH
Fixed Version: 12.3.0
Link: CVE-2026-59204

Check failure on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

Pillow: Pillow: Denial of service via crafted PDF stream High

Package: pillow
Installed Version: 12.2.0
Vulnerability CVE-2026-59200
Severity: HIGH
Fixed Version: 12.3.0
Link: CVE-2026-59200

Check failure on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

Pillow: Pillow: Denial of Service via out-of-bounds write in image processing High

Package: pillow
Installed Version: 12.2.0
Vulnerability CVE-2026-59199
Severity: HIGH
Fixed Version: 12.3.0
Link: CVE-2026-59199

Check failure on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

Pillow: Pillow: Native heap out-of-bounds write High

Package: pillow
Installed Version: 12.2.0
Vulnerability CVE-2026-59197
Severity: HIGH
Fixed Version: 12.3.0
Link: CVE-2026-59197

Check failure on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

python-pillow: Pillow: Denial of Service via crafted GD 2.x image file High

Package: pillow
Installed Version: 12.2.0
Vulnerability CVE-2026-55380
Severity: HIGH
Fixed Version: 12.3.0
Link: CVE-2026-55380

Check failure on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

python-pillow: Pillow: Denial of Service via crafted BDF font file High

Package: pillow
Installed Version: 12.2.0
Vulnerability CVE-2026-55379
Severity: HIGH
Fixed Version: 12.3.0
Link: CVE-2026-55379

Check failure on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files High

Package: pillow
Installed Version: 12.2.0
Vulnerability CVE-2026-54060
Severity: HIGH
Fixed Version: 12.3.0
Link: CVE-2026-54060

Check failure on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

python-pillow: Pillow: Denial of Service via crafted PCF font data High

Package: pillow
Installed Version: 12.2.0
Vulnerability CVE-2026-54059
Severity: HIGH
Fixed Version: 12.3.0
Link: CVE-2026-54059

Check failure on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image High

Package: pillow
Installed Version: 12.2.0
Vulnerability CVE-2026-54058
Severity: HIGH
Fixed Version: 12.3.0
Link: CVE-2026-54058

Check failure on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API High

Package: pillow
Installed Version: 12.2.0
Vulnerability CVE-2026-59205
Severity: HIGH
Fixed Version: 12.3.0
Link: CVE-2026-59205

Check failure on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

cryptography is a package designed to expose cryptographic primitives ... High

Package: cryptography
Installed Version: 48.0.0
Vulnerability CVE-2026-69247
Severity: HIGH
Fixed Version: 50.0.0
Link: CVE-2026-69247

Check failure on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

python-pyjwt: PyJWT: Authentication bypass due to forged JSON Web Tokens High

Package: pyjwt
Installed Version: 2.12.1
Vulnerability CVE-2026-48526
Severity: HIGH
Fixed Version: 2.13.0
Link: CVE-2026-48526

Check failure on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

Vulnerable OpenSSL included in cryptography wheels High

Package: cryptography
Installed Version: 48.0.0
Vulnerability GHSA-537c-gmf6-5ccf
Severity: HIGH
Fixed Version: 48.0.1
Link: GHSA-537c-gmf6-5ccf

Check failure on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

python-cryptography is a package designed to expose cryptographic prim ... High

Package: cryptography
Installed Version: 48.0.0
Vulnerability CVE-2026-69249
Severity: HIGH
Fixed Version: 49.0.0
Link: CVE-2026-69249

Check warning on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

python-pillow: Pillow: Arbitrary command injection via shell metacharacters in file paths Medium

Package: pillow
Installed Version: 12.2.0
Vulnerability CVE-2026-55798
Severity: MEDIUM
Fixed Version: 12.3.0
Link: CVE-2026-55798

Check warning on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

Pillow: Pillow: Information disclosure via TGA RLE encoder out-of-bounds read Medium

Package: pillow
Installed Version: 12.2.0
Vulnerability CVE-2026-59198
Severity: MEDIUM
Fixed Version: 12.3.0
Link: CVE-2026-59198

Check warning on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

Pillow: Pillow: Denial of Service via crafted EPS file Medium

Package: pillow
Installed Version: 12.2.0
Vulnerability CVE-2026-59203
Severity: MEDIUM
Fixed Version: 12.3.0
Link: CVE-2026-59203

Check warning on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

cryptography is a package designed to expose cryptographic primitives ... Medium

Package: cryptography
Installed Version: 48.0.0
Vulnerability CVE-2026-69248
Severity: MEDIUM
Fixed Version: 49.0.0
Link: CVE-2026-69248

Check warning on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders Medium

Package: langchain
Installed Version: 1.3.0
Vulnerability CVE-2026-55443
Severity: MEDIUM
Fixed Version: 1.3.9
Link: CVE-2026-55443

Check warning on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

python-pyjwt: PyJWT: Denial of Service via processing of crafted detached JWS tokens Medium

Package: pyjwt
Installed Version: 2.12.1
Vulnerability CVE-2026-48525
Severity: MEDIUM
Fixed Version: 2.13.0
Link: CVE-2026-48525

Check warning on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

python-pyjwt: PyJWT: Verifier-side algorithm bypass leads to unauthorized information access Medium

Package: pyjwt
Installed Version: 2.12.1
Vulnerability CVE-2026-48523
Severity: MEDIUM
Fixed Version: 2.13.0
Link: CVE-2026-48523

Check warning on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

python-pyjwt: PyJWT: Server-Side Request Forgery (SSRF) via uncontrolled URL fetching in PyJWKClient Medium

Package: pyjwt
Installed Version: 2.12.1
Vulnerability CVE-2026-48522
Severity: MEDIUM
Fixed Version: 2.13.0
Link: CVE-2026-48522

Check warning on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

python-idna: idna: Denial of Service via specially crafted long inputs Medium

Package: idna
Installed Version: 3.10
Vulnerability CVE-2026-45409
Severity: MEDIUM
Fixed Version: 3.15
Link: CVE-2026-45409

Check warning on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

JWCrypto: python-cryptography: python: JWCrypto: Memory exhaustion via crafted compressed JWE tokens Medium

Package: jwcrypto
Installed Version: 1.5.6
Vulnerability CVE-2026-39373
Severity: MEDIUM
Fixed Version: 1.5.7
Link: CVE-2026-39373

Check notice on line 1 in a2a/weather_service/uv.lock

See this annotation in the file changed.

Code scanning / Trivy

python-pyjwt: PyJWT: Denial of Service via unverified JSON Web Token key IDs Low

Package: pyjwt
Installed Version: 2.12.1
Vulnerability CVE-2026-48524
Severity: LOW
Fixed Version: 2.13.0
Link: CVE-2026-48524