Skip to content

Comments

Update urllib3 to 2.6.3+#134

Closed
kstribrnAmzn wants to merge 2 commits intoFreeRTOS:mainfrom
kstribrnAmzn:urlLibFix2
Closed

Update urllib3 to 2.6.3+#134
kstribrnAmzn wants to merge 2 commits intoFreeRTOS:mainfrom
kstribrnAmzn:urlLibFix2

Conversation

@kstribrnAmzn
Copy link
Member

Description of changes:
This dependency update adds decompression-bomb
safeguards to HTTP redirects. See CVE-2026-21441.

https://nvd.nist.gov/vuln/detail/CVE-2026-21441

The fix - https://github.com/urllib3/urllib3/releases/tag/2.6.3

Issue #, if available:
https://github.com/aws/aws-iot-device-sdk-embedded-C/security/dependabot/22

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@kstribrnAmzn kstribrnAmzn marked this pull request as draft January 13, 2026 18:28
@kstribrnAmzn kstribrnAmzn marked this pull request as ready for review January 13, 2026 18:28
@kstribrnAmzn
Copy link
Member Author

I'm going to close this PR and reopen it to trigger the link verification check.

@kstribrnAmzn kstribrnAmzn deleted the urlLibFix2 branch January 13, 2026 18:29
@kstribrnAmzn kstribrnAmzn restored the urlLibFix2 branch January 13, 2026 18:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant