[Security] 26.9.1 dependency-floor review: raise floors for known, reachable advisories (evidence-driven)
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 3/5
- Tempo stimato
- 1-2 giorni
- Idoneità per principianti
- 40/100
Direzione di ricerca
Review the evidence base from issue #1949 to confirm each advisory's reachability. Update version floors in pyproject.toml for the listed dependencies, ensuring the changes resolve cleanly with 'just install-dev'. Run CI tests to verify compatibility. Document decisions in CHANGELOG and add comments where non-obvious.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
Review and raise dependency floors in pyproject.toml where there is a known, reachable
security advisory, using the reproducible evidence base from #1949 as the source of truth. This is a
single tracking issue with a tiered checklist (one coordinated PR, or a few small ones).
Governing principles (per the #1949 discussion):
- Library boundary. autobahn is a library; a floor forces every consumer up, so raise a floor
only for a declared dependency where the advisory is reachable through autobahn's own use
(or where the dep is a dev/build tool, which costs consumers nothing). - Scan transitively (report), floor selectively. A transitive finding is evidence, not a floor
driver — do not add direct pins for transitive/unused deps; push those upstream to the owning dep. - Evidence-backed, not scanner-authoritative. The scanners in #1949 are DB consumers; the CVE
IDs below are the starting proposal from a manual audit and MUST be reconciled against the
autobahn-security-evidence-<tag>.zipartifact before the implementing PR merges. Exploitability /
applicability stays a human call (recorded in the #1949 annotations/allowlist).
Depends on #1949 (evidence base first). Already landed: cryptography>=50 and the cbor2
runtime split (#1947).
Tier 1 — runtime deps on the reachable attack surface (raise)
autobahn processes untrusted WAMP input with these and/or uses them for TLS/crypto, so advisories are
reachable. (Provisional — confirm each against #1949.)
| Dep | Current | Proposed | Advisory (to verify via #1949) |
|---|---|---|---|
msgpack |
>=1.0.2 |
>=1.2.1 |
CVE-2026-57585 / GHSA-6v7p-g79w-8964 — OOB read / UAF on Unpacker reuse after a caught decode error; directly relevant to WAMP MessagePack decoding |
ujson |
>=4.0.2 |
>=5.13.0 |
CVE-2026-54911 / GHSA-3j69-69wj-xqx2 — affects ≤5.12.1, fixed 5.13.0 |
brotli |
>=1.0.0 |
>=1.2.0 |
Decompression-bomb hardening (urllib3 guidance, CVE-2026-44432 scenario); complements autobahn's own compressed-payload fix (CVE-2026-77528, 26.7.1) |
brotlicffi |
>=1.0.0 |
>=1.2.0.0 |
Allocation/resource-exhaustion below 1.2.0.0 |
pyopenssl ([encryption]) |
>=20.0.1 |
>=26.0.0 |
CVE-2026-27459 (DTLS cookie buffer overflow) + CVE-2026-27448 (TLS callback fail-open), fixed 26.0.0 |
pynacl ([encryption]) |
>=1.4.0 |
>=1.6.2 |
CVE-2025-69277 — libsodium 1.0.20 update in 1.6.2 (cryptosign signing primitive) |
Already done (#1947): cryptography>=50, cbor2>=6.1.0(CPython)/==5.9.0(PyPy).
Tier 2 — dev/build tools (raise; zero downstream cost)
These execute locally in dev/CI, not in consumers' installs. (Provisional — confirm via #1949.)
| Dep | Current | Proposed | Advisory |
|---|---|---|---|
wheel ([build-tools],[dev]) |
>=0.36.2 |
>=0.38.1 |
CVE-2022-40898 — ReDoS in filename validation |
pytest ([dev]) |
>=3.4.2 |
>=9.0.3 |
CVE-2025-71176 — insecure tmpdir handling |
pyyaml ([dev]) |
>=4.2b4 |
>=6.0.2 |
crosses CVE-2017-18342 / CVE-2019-20477 / CVE-2020-14343 (unsafe load) |
setuptools ([dev]) |
>=70.0.0 |
>=83.0.0 |
CVE-2025-47273 (≥78.1.1) + CVE-2026-59890 (<83.0.0) |
jinja2 ([benchmark]) |
>=3.0.0 |
>=3.1.6 |
CVE-2025-27516 sandbox escape (+ CVE-2024-56201) |
Tier 3 — deliberate call, decision deferred until #1949 evidence exists
| Dep | Current | Candidate | Notes |
|---|---|---|---|
twisted ([twisted],[dev]) |
>=22.10.0 |
>=26.4.0? |
CVE-2026-42304 (twisted.names DNS-compression DoS, fixed 26.4.0rc2/26.4.0). Biggest downstream impact — a hard floor forces all consumers up. Leaning to bump anyway: autobahn is a library but is also used to implement listening servers (WebSocket), and 22.10.0→26.4.0 almost certainly spans multiple CVEs. Decide once #1949 produces a real evidence base showing the exact advisories in that range and their reachability. |
Explicitly NOT changing (documented — no advisory / not reachable)
Keep the compatibility floor; do not bump on age alone: txaio, cffi, hyperlink,
importlib-resources, u-msgpack-python, zope.interface, attrs, service-identity
(its own cryptography>=47 need is already covered by our >=50), pytrie, qrcode, base58,
argon2-cffi, passlib (1.7.4 is latest upstream; maintenance concern, not a CVE), docs extras, etc.
ecdsa/ Minerva (CVE-2024-23342): N/A. autobahn's onlyecdsause is secp256k1 BIP32
derivation math (mnemonic.py), never P-256 signing; signing is Ed25519 (nacl). No floor needed
on Minerva grounds. (CVE-2026-33936 DER-parse DoS is also not reachable — derivation consumes raw
32-byte scalars, not DER keys.) Record as an allowlist entry in #1949.- Vendored FlatBuffers is out of scope here — handled in a separate, coordinated
autobahn + zlmdb pair of issues (a Python package scan cannot bump vendored C++, and the version
is locked to zlmdb viacheck_zlmdb_flatbuffers_version_in_sync()). - Transitive-only findings (e.g.
numpyviabjdata) are recorded informationally, not turned
into direct floors.
Acceptance criteria
- Each proposed floor reconciled against the #1949 evidence base (advisory confirmed, version confirmed).
- Tier 1 + Tier 2 floors raised in
pyproject.toml; CHANGELOG26.9.1"Security"/"Dependencies" entries added. - Twisted decision made and recorded (bump to
>=26.4.0, or documented deferral) based on the evidence base. - "Not changing" set documented (this issue + a pyproject comment where non-obvious).
-
just install-devresolves cleanly on CPython + PyPy; CI green.
Notes / links
- Evidence base: #1949. Already landed: #1947 (cryptography/cbor2).
- FlatBuffers: separate autobahn + zlmdb issues (coordinated bump).
- This is a CVE/advisory-driven review of declared deps; it is not an SBOM audit of a consuming
application's deployed environment (that is a separate boundary — see #1949).
- Lingua principale
- Python
- Stelle
- 2.5k
- Fork
- 770
- Merge medio
- 2g 6h
- PR unite (30g)
- 10
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di crossbario/autobahn-python
-
CI-CD enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
crossbario/autobahn-python#1945 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
bug CI-CD
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
crossbario/autobahn-python#1932 ·
I maintainer di solito rispondono entro 1 giorno
-
CI-CD enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
crossbario/autobahn-python#1829 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
crossbario/autobahn-python#1963 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 68/100
crossbario/autobahn-python#1962 ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di crossbario/autobahn-python
Issue simili
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
mishraprafful/multihull#150 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 66/100
python-caldav/caldav#735 ·
I maintainer di solito rispondono entro 1 giorno
-
bug triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
mealie-recipes/mealie#8682 ·
I maintainer di solito rispondono entro 1 giorno
-
good first issue lane:repo
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100