Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

[Security] 26.9.1 dependency-floor review: raise floors for known, reachable advisories (evidence-driven)

Aperta
#1,950 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
40/100
Tipo di issue
Refactoring
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
python
Ambito
backend, security

Direzione di ricerca

Review the evidence base from issue #1949 to confirm each advisory's reachability. Update version floors in pyproject.toml for the listed dependencies, ensuring the changes resolve cleanly with 'just install-dev'. Run CI tests to verify compatibility. Document decisions in CHANGELOG and add comments where non-obvious.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Summary

Review and raise dependency floors in pyproject.toml where there is a known, reachable
security advisory, using the reproducible evidence base from #1949 as the source of truth. This is a
single tracking issue with a tiered checklist (one coordinated PR, or a few small ones).

Governing principles (per the #1949 discussion):

  • Library boundary. autobahn is a library; a floor forces every consumer up, so raise a floor
    only for a declared dependency where the advisory is reachable through autobahn's own use
    (or where the dep is a dev/build tool, which costs consumers nothing).
  • Scan transitively (report), floor selectively. A transitive finding is evidence, not a floor
    driver — do not add direct pins for transitive/unused deps; push those upstream to the owning dep.
  • Evidence-backed, not scanner-authoritative. The scanners in #1949 are DB consumers; the CVE
    IDs below are the starting proposal from a manual audit and MUST be reconciled against the
    autobahn-security-evidence-<tag>.zip artifact before the implementing PR merges. Exploitability /
    applicability stays a human call (recorded in the #1949 annotations/allowlist).

Depends on #1949 (evidence base first). Already landed: cryptography>=50 and the cbor2
runtime split (#1947).

Tier 1 — runtime deps on the reachable attack surface (raise)

autobahn processes untrusted WAMP input with these and/or uses them for TLS/crypto, so advisories are
reachable. (Provisional — confirm each against #1949.)

Dep Current Proposed Advisory (to verify via #1949)
msgpack >=1.0.2 >=1.2.1 CVE-2026-57585 / GHSA-6v7p-g79w-8964 — OOB read / UAF on Unpacker reuse after a caught decode error; directly relevant to WAMP MessagePack decoding
ujson >=4.0.2 >=5.13.0 CVE-2026-54911 / GHSA-3j69-69wj-xqx2 — affects ≤5.12.1, fixed 5.13.0
brotli >=1.0.0 >=1.2.0 Decompression-bomb hardening (urllib3 guidance, CVE-2026-44432 scenario); complements autobahn's own compressed-payload fix (CVE-2026-77528, 26.7.1)
brotlicffi >=1.0.0 >=1.2.0.0 Allocation/resource-exhaustion below 1.2.0.0
pyopenssl ([encryption]) >=20.0.1 >=26.0.0 CVE-2026-27459 (DTLS cookie buffer overflow) + CVE-2026-27448 (TLS callback fail-open), fixed 26.0.0
pynacl ([encryption]) >=1.4.0 >=1.6.2 CVE-2025-69277 — libsodium 1.0.20 update in 1.6.2 (cryptosign signing primitive)

Already done (#1947): cryptography>=50, cbor2>=6.1.0(CPython)/==5.9.0(PyPy).

Tier 2 — dev/build tools (raise; zero downstream cost)

These execute locally in dev/CI, not in consumers' installs. (Provisional — confirm via #1949.)

Dep Current Proposed Advisory
wheel ([build-tools],[dev]) >=0.36.2 >=0.38.1 CVE-2022-40898 — ReDoS in filename validation
pytest ([dev]) >=3.4.2 >=9.0.3 CVE-2025-71176 — insecure tmpdir handling
pyyaml ([dev]) >=4.2b4 >=6.0.2 crosses CVE-2017-18342 / CVE-2019-20477 / CVE-2020-14343 (unsafe load)
setuptools ([dev]) >=70.0.0 >=83.0.0 CVE-2025-47273 (≥78.1.1) + CVE-2026-59890 (<83.0.0)
jinja2 ([benchmark]) >=3.0.0 >=3.1.6 CVE-2025-27516 sandbox escape (+ CVE-2024-56201)

Tier 3 — deliberate call, decision deferred until #1949 evidence exists

Dep Current Candidate Notes
twisted ([twisted],[dev]) >=22.10.0 >=26.4.0? CVE-2026-42304 (twisted.names DNS-compression DoS, fixed 26.4.0rc2/26.4.0). Biggest downstream impact — a hard floor forces all consumers up. Leaning to bump anyway: autobahn is a library but is also used to implement listening servers (WebSocket), and 22.10.0→26.4.0 almost certainly spans multiple CVEs. Decide once #1949 produces a real evidence base showing the exact advisories in that range and their reachability.

Explicitly NOT changing (documented — no advisory / not reachable)

Keep the compatibility floor; do not bump on age alone: txaio, cffi, hyperlink,
importlib-resources, u-msgpack-python, zope.interface, attrs, service-identity
(its own cryptography>=47 need is already covered by our >=50), pytrie, qrcode, base58,
argon2-cffi, passlib (1.7.4 is latest upstream; maintenance concern, not a CVE), docs extras, etc.

  • ecdsa / Minerva (CVE-2024-23342): N/A. autobahn's only ecdsa use is secp256k1 BIP32
    derivation math (mnemonic.py), never P-256 signing; signing is Ed25519 (nacl). No floor needed
    on Minerva grounds. (CVE-2026-33936 DER-parse DoS is also not reachable — derivation consumes raw
    32-byte scalars, not DER keys.) Record as an allowlist entry in #1949.
  • Vendored FlatBuffers is out of scope here — handled in a separate, coordinated
    autobahn + zlmdb pair of issues (a Python package scan cannot bump vendored C++, and the version
    is locked to zlmdb via check_zlmdb_flatbuffers_version_in_sync()).
  • Transitive-only findings (e.g. numpy via bjdata) are recorded informationally, not turned
    into direct floors.

Acceptance criteria

  • Each proposed floor reconciled against the #1949 evidence base (advisory confirmed, version confirmed).
  • Tier 1 + Tier 2 floors raised in pyproject.toml; CHANGELOG 26.9.1 "Security"/"Dependencies" entries added.
  • Twisted decision made and recorded (bump to >=26.4.0, or documented deferral) based on the evidence base.
  • "Not changing" set documented (this issue + a pyproject comment where non-obvious).
  • just install-dev resolves cleanly on CPython + PyPy; CI green.

Notes / links

  • Evidence base: #1949. Already landed: #1947 (cryptography/cbor2).
  • FlatBuffers: separate autobahn + zlmdb issues (coordinated bump).
  • This is a CVE/advisory-driven review of declared deps; it is not an SBOM audit of a consuming
    application's deployed environment (that is a separate boundary — see #1949).
Lingua principale
Python
Stelle
2.5k
Fork
770
Merge medio
2g 6h
PR unite (30g)
10

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di crossbario/autobahn-python

Tutte le issue di crossbario/autobahn-python

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.