Skip to content

Fix CVE-2026-21441, CVE-2025-66471, and CVE-2025-66418 by bumping urllib3 to ~=2.6.3#199

Open
mytreya-rh wants to merge 1 commit intooperator-framework:mainfrom
mytreya-rh:fix_CVE-2025-66471
Open

Fix CVE-2026-21441, CVE-2025-66471, and CVE-2025-66418 by bumping urllib3 to ~=2.6.3#199
mytreya-rh wants to merge 1 commit intooperator-framework:mainfrom
mytreya-rh:fix_CVE-2025-66471

Conversation

@mytreya-rh
Copy link

Description of the change:
Fix issues:
#191 by bumping urllib3 to 2.6.0
and
#197 #198 by regenerating the Pipfile.lock

Motivation for the change:
Closes #191
Closes #197
Closes #198

/cc @chiragkyal
/cc @acornett21

@openshift-ci openshift-ci bot requested a review from acornett21 February 25, 2026 05:43
@openshift-ci
Copy link

openshift-ci bot commented Feb 25, 2026

@mytreya-rh: GitHub didn't allow me to request PR reviews from the following users: chiragkyal.

Note that only operator-framework members and repo collaborators can review this PR, and authors cannot review their own PRs.

Details

In response to this:

Description of the change:
Fix issues:
#191 by bumping urllib3 to 2.6.0
and
#197 #198 by regenerating the Pipfile.lock

Motivation for the change:
Closes #191
Closes #197
Closes #198

/cc @chiragkyal
/cc @acornett21

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

@mytreya-rh mytreya-rh force-pushed the fix_CVE-2025-66471 branch 2 times, most recently from ceee207 to 065e439 Compare February 25, 2026 06:54
@chiragkyal
Copy link
Contributor

/ok-to-test

@openshift-ci
Copy link

openshift-ci bot commented Feb 25, 2026

@chiragkyal: Cannot trigger testing until a trusted user reviews the PR and leaves an /ok-to-test message.

Details

In response to this:

/ok-to-test

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository.

operator-framework#191
by bumping urllib3 to 2.6.0
and
operator-framework#197
operator-framework#198
by regenerating the Pipfile.lock
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Upgrade pyasn1 version to 0.6.2 Upgrade cryptography version to 46.0.5 urllib3 upgrade to 2.6.3

3 participants