chore(deps-dev): bump urllib3 from 2.5.0 to 2.6.0 #1397
Closed
Microsoft GitHub Policy Service / GitOps/AdvancedSecurity
failed
Jan 8, 2026 in 0s
Dependency Review
Dependency review detected vulnerable
Details
Dependency review summary
We have found 1 vulnerable package(s).
Vulnerability
Vulnerabilities were filtered by minimum severity Moderate.
| Dependency | File Name | Version | Vulnerability | Severity |
|---|---|---|---|---|
| urllib3 | requirements-dev.txt | 2.6.0 | Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API) | High |
Loading