Skip to content

security: bump urllib3 floor to 2.6.3 for CVE-2026-21441 - #1869

Open
jacalata wants to merge 1 commit into
developmentfrom
jac/urllib3-cve-2026-21441
Open

security: bump urllib3 floor to 2.6.3 for CVE-2026-21441#1869
jacalata wants to merge 1 commit into
developmentfrom
jac/urllib3-cve-2026-21441

Conversation

@jacalata

@jacalata jacalata commented Aug 20, 2026

Copy link
Copy Markdown
Contributor

Summary

FOSSA flagged CVE-2026-21441 (GHSA-38jv-5279-wg99, 8.9 High) against urllib3 2.6.0. The fix landed in urllib3 2.6.3: streaming decompression safeguards were bypassed when HTTP redirects were followed.

The existing urllib3>=2.6.0,<3 specifier in pyproject.toml already permits 2.6.3, but because 2.6.0 remains a resolvable install, Dependabot did not open a range-bump PR, and the repo did not have Dependabot's security-updates side expressed in its config either. This PR closes that gap.

Changes

  • pyproject.toml — raise the urllib3 floor to urllib3>=2.6.3,<3 so fresh resolves cannot land on a vulnerable release. The <3 upper bound is unchanged; this is a floor bump within the existing supported range.
  • .github/dependabot.yml — add open-pull-requests-limit: 10 to both the pip and github-actions ecosystems so security PRs are not squeezed out by the default cap of 5. Add a comment on the pip block noting that security advisories fire independently of the weekly schedule as long as "Dependabot security updates" is enabled under Settings -> Code security.
  • CHANGELOG.md — add an ## Unreleased bullet naming the CVE, the GHSA, and the reason for the bump.

Notes

TSC's manual redirect walker (#1848) disables urllib3's built-in follower on new code paths, but downstream callers using urllib3 directly (and TSC endpoints that predate #1848) still relied on the built-in path — so the floor bump closes the gap for all callers rather than only the paths already touched by #1848.

Test plan

  • python -c "import tomllib; tomllib.loads(open('pyproject.toml', 'rb').read().decode())" parses.
  • python -c "import yaml; yaml.safe_load(open('.github/dependabot.yml'))" parses.
  • CI green on the PR.

Generated with Claude Code

FOSSA flagged CVE-2026-21441 (GHSA-38jv-5279-wg99, 8.9 High) against
urllib3 2.6.0. The fix landed in urllib3 2.6.3: streaming decompression
safeguards were bypassed when HTTP redirects were followed.

The existing `urllib3>=2.6.0,<3` specifier already permits 2.6.3, but
because 2.6.0 remains a resolvable install, Dependabot did not open a
range-bump PR, and this repo did not have the security-updates side of
Dependabot expressed in its config either. This change:

  * Raises the floor in pyproject.toml to `urllib3>=2.6.3,<3` so fresh
    resolves cannot land on a vulnerable release.
  * Adds `open-pull-requests-limit: 10` to both dependabot ecosystems so
    security PRs are not squeezed out by the default cap of 5, and
    documents on the pip block that security advisories fire
    independently of the weekly schedule as long as "Dependabot
    security updates" is enabled under Settings -> Code security.
  * Adds a CHANGELOG entry naming the CVE and GHSA.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

Coverage

Coverage Report
FileStmtsMissCoverMissing
tableauserverclient
   __init__.py50100% 
   config.py150100% 
   datetime_helpers.py2511 96%
   exponential_backoff.py200100% 
   filesys_helpers.py310100% 
   namespace.py2533 88%
tableauserverclient/bin
   __init__.py20100% 
   _version.py358212212 41%
tableauserverclient/helpers
   __init__.py10100% 
   logging.py20100% 
   strings.py3111 97%
tableauserverclient/models
   __init__.py460100% 
   collection_item.py4177 83%
   column_item.py553232 42%
   connection_credentials.py351111 69%
   connection_item.py941414 85%
   custom_view_item.py1442121 85%
   data_acceleration_report_item.py5411 98%
   data_alert_item.py15844 97%
   data_freshness_policy_item.py1551515 90%
   database_item.py2073636 83%
   datasource_item.py3001212 96%
   dqw_item.py10455 95%
   exceptions.py40100% 
   extensions_item.py13244 97%
   extract_item.py4444 91%
   favorites_item.py6988 88%
   fileupload_item.py190100% 
   flow_item.py1491010 93%
   flow_run_item.py710100% 
   group_item.py8966 93%
   groupset_item.py4977 86%
   interval_item.py1823232 82%
   job_item.py1921010 95%
   linked_tasks_item.py7911 99%
   location_item.py2922 93%
   metric_item.py1291313 90%
   oidc_item.py6333 95%
   pagination_item.py3411 97%
   permissions_item.py1111212 89%
   project_item.py2073131 85%
   property_decorators.py1001818 82%
   reference_item.py2622 92%
   revision_item.py5911 98%
   schedule_item.py20966 97%
   server_info_item.py3777 81%
   site_item.py6361313 98%
   subscription_item.py10122 98%
   table_item.py1191818 85%
   tableau_auth.py612525 59%
   tableau_types.py2711 96%
   tag_item.py150100% 
   target.py60100% 
   task_item.py5622 96%
   user_item.py3231616 95%
   view_item.py2201616 93%
   virtual_connection_item.py6488 88%
   webhook_item.py6911 99%
   workbook_item.py3621616 96%
tableauserverclient/server
   __init__.py90100% 
   exceptions.py40100% 
   filter.py2911 97%
   pager.py3311 97%
   query.py1431515 90%
   request_factory.py1335195195 85%
   request_options.py38655 99%
   server.py1882323 88%
   sort.py60100% 
tableauserverclient/server/endpoint
   __init__.py350100% 
   auth_endpoint.py731010 86%
   custom_views_endpoint.py1521212 92%
   data_acceleration_report_endpoint.py210100% 
   data_alert_endpoint.py942323 76%
   databases_endpoint.py1113030 73%
   datasources_endpoint.py3233333 90%
   default_permissions_endpoint.py4433 93%
   dqw_endpoint.py451616 64%
   endpoint.py2592424 91%
   exceptions.py7966 92%
   extensions_endpoint.py310100% 
   favorites_endpoint.py942222 77%
   fileuploads_endpoint.py510100% 
   flow_runs_endpoint.py6299 85%
   flow_task_endpoint.py2122 90%
   flows_endpoint.py1985353 73%
   groups_endpoint.py12699 93%
   groupsets_endpoint.py7277 90%
   jobs_endpoint.py6799 87%
   linked_tasks_endpoint.py370100% 
   metadata_endpoint.py881414 84%
   metrics_endpoint.py5566 89%
   oidc_endpoint.py4211 98%
   permissions_endpoint.py4433 93%
   projects_endpoint.py1782424 87%
   resource_tagger.py1273535 72%
   schedules_endpoint.py1191111 91%
   server_info_endpoint.py361010 72%
   sites_endpoint.py1302727 79%
   subscriptions_endpoint.py561414 75%
   tables_endpoint.py1103636 67%
   tasks_endpoint.py6366 90%
   users_endpoint.py18388 96%
   views_endpoint.py15099 94%
   virtual_connections_endpoint.py1131010 91%
   webhooks_endpoint.py5499 83%
   workbooks_endpoint.py3382222 93%
TOTAL12064142488% 

@jacalata jacalata added the dependencies Pull requests that update a dependency file label Aug 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants