Skip to content

Comments

Update urllib3 to 2.6.3+#136

Merged
kstribrnAmzn merged 1 commit intoFreeRTOS:mainfrom
kstribrnAmzn:linkVerifierFix
Jan 13, 2026
Merged

Update urllib3 to 2.6.3+#136
kstribrnAmzn merged 1 commit intoFreeRTOS:mainfrom
kstribrnAmzn:linkVerifierFix

Conversation

@kstribrnAmzn
Copy link
Member

Description of changes:
This dependency update adds decompression-bomb
safeguards to HTTP redirects. See CVE-2026-21441.

https://nvd.nist.gov/vuln/detail/CVE-2026-21441

The fix - https://github.com/urllib3/urllib3/releases/tag/2.6.3

Issue #, if available:
https://github.com/aws/aws-iot-device-sdk-embedded-C/security/dependabot/22

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

This dependency update adds decompression-bomb
safeguards to HTTP redirects. See  CVE-2026-21441.

https://nvd.nist.gov/vuln/detail/CVE-2026-21441
@kstribrnAmzn kstribrnAmzn merged commit e604ea1 into FreeRTOS:main Jan 13, 2026
36 checks passed
@kstribrnAmzn kstribrnAmzn deleted the linkVerifierFix branch January 13, 2026 22:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants