Skip to content

fix: pin urllib3 to 2.7.0 to fix CVE-2026-44431 and CVE-2026-44432#753

Merged
ezhang6811 merged 3 commits into
aws-observability:release/v0.17.xfrom
ezhang6811:urllib3-fix
May 22, 2026
Merged

fix: pin urllib3 to 2.7.0 to fix CVE-2026-44431 and CVE-2026-44432#753
ezhang6811 merged 3 commits into
aws-observability:release/v0.17.xfrom
ezhang6811:urllib3-fix

Conversation

@ezhang6811
Copy link
Copy Markdown
Contributor

Issue #, if available:

Description of changes:
Pins urllib3 to 2.7.0 for Python 3.10 or higher (not compatible with 3.9), to fix CVE-2026-44431 and CVE-2026-44432

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

@ezhang6811 ezhang6811 requested a review from a team as a code owner May 21, 2026 23:44
Copy link
Copy Markdown
Contributor

@vastin vastin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@ezhang6811 ezhang6811 enabled auto-merge (squash) May 21, 2026 23:52
@ezhang6811 ezhang6811 merged commit 4d0faad into aws-observability:release/v0.17.x May 22, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants