Skip to content

πŸ”’ Security Alerts β€” IBM/ibmdotcom-tutorialsΒ #136

Description

@security-ops-bot

πŸ”’ Security Alerts β€” IBM/ibmdotcom-tutorials

Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.

SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only β€”
they will never trigger warnings or archiving.

πŸ’‘ Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings β†’ Advanced Security β†’ Dependabot security updates β†’ Enable.

πŸ“– New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.

Attention: @thinkscientist

Dependabot Alerts

Severity CVE/GHSA Package Affected Patched Fix PR
πŸ”΄ critical CVE-2026-45833 chromadb >= 0.4.17, <= 1.5.9 β€” β€”
πŸ”΄ critical CVE-2026-37004 litellm < 1.83.7 1.83.7 β€”
πŸ”΄ critical CVE-2026-78676 GitPython <= 3.1.58 3.1.59 β€”
🟠 high CVE-2026-42035 axios >= 1.0.0, < 1.15.1 1.15.1 β€”
🟠 high CVE-2026-42033 axios >= 1.0.0, < 1.15.1 1.15.1 β€”
🟠 high CVE-2026-42561 python-multipart < 0.0.27 0.0.27 β€”
🟠 high CVE-2026-44307 Mako <= 1.3.11 1.3.12 β€”
🟠 high CVE-2026-44843 langchain-core <= 0.3.84 0.3.85 β€”
🟠 high CVE-2026-44431 urllib3 >= 1.23, < 2.7.0 2.7.0 β€”
🟠 high CVE-2026-45134 langsmith < 0.8.0 0.8.0 β€”
🟠 high CVE-2026-42264 axios >= 1.0.0, < 1.15.2 1.15.2 β€”
🟠 high CVE-2026-31240 mem0ai <= 1.0.0 β€” β€”
🟠 high CVE-2026-42043 axios >= 1.0.0, < 1.15.1 1.15.1 β€”
🟠 high CVE-2026-45623 postcss <= 8.5.11 8.5.12 β€”
🟠 high CVE-2026-73646 postcss <= 8.5.17 8.5.18 β€”
🟠 high CVE-2026-59884 pyasn1 < 0.6.4 0.6.4 β€”
🟠 high CVE-2026-69244 aiohttp <= 3.14.2 3.14.3 β€”
🟠 high GHSA-3f7w-8rr8-f37f GitPython <= 3.1.56 3.1.57 β€”
🟠 high CVE-2026-69247 cryptography >= 44.0.0, < 50.0.0 50.0.0 β€”
🟠 high CVE-2026-18446 fast-uri >= 3.0.0, < 3.1.5 3.1.5 β€”
🟠 high GHSA-5p4m-2wfm-xmqj js-yaml >= 4.0.0, < 4.3.1 4.3.1 β€”
🟠 high CVE-2026-76219 GitPython <= 3.1.57 3.1.58 β€”
🟠 high CVE-2026-76218 GitPython <= 3.1.57 3.1.58 β€”
🟠 high CVE-2026-76220 GitPython <= 3.1.57 3.1.58 β€”
🟠 high GHSA-jm78-9fvv-mhgr GitPython <= 3.1.57 3.1.58 β€”
🟠 high CVE-2026-76222 GitPython <= 3.1.57 3.1.58 β€”
🟠 high CVE-2026-6322 fast-uri >= 3.0.0, <= 3.1.1 3.1.2 β€”
🟠 high CVE-2026-6321 fast-uri >= 3.0.0, <= 3.1.0 3.1.1 β€”
🟠 high CVE-2026-45831 chromadb >= 0.5.0, <= 1.5.9 β€” β€”
🟠 high CVE-2026-45830 chromadb >= 0.4.17, <= 1.5.9 β€” β€”
🟠 high CVE-2026-73088 browserslist <= 4.28.6 4.28.7 β€”
🟠 high CVE-2026-73086 nanoid < 3.3.12 3.3.12 β€”
🟠 high CVE-2026-76172 fast-uri >= 3.0.0, < 3.1.6 3.1.6 β€”
🟠 high CVE-2026-75975 fast-uri >= 3.0.0, < 3.1.6 3.1.6 β€”
🟠 high CVE-2026-62240 crewai-tools < 1.15.1 1.15.1 β€”
🟠 high CVE-2026-69249 cryptography >= 42.0.0, <= 48.0.0 49.0.0 β€”
🟠 high CVE-2026-78677 GitPython <= 3.1.58 3.1.59 β€”
🟠 high CVE-2026-78675 GitPython <= 3.1.58 3.1.59 β€”
🟠 high CVE-2026-84375 js-yaml >= 4.0.0, < 4.3.2 4.3.2 β€”
🟑 medium CVE-2026-42036 axios >= 1.0.0, < 1.15.1 1.15.1 β€”
🟑 medium CVE-2026-42044 axios >= 1.0.0, < 1.15.2 1.15.2 β€”
🟑 medium CVE-2026-42038 axios >= 1.0.0, < 1.15.1 1.15.1 β€”
🟑 medium CVE-2026-42037 axios >= 1.0.0, < 1.15.1 1.15.1 β€”
🟑 medium CVE-2026-42034 axios >= 1.0.0, < 1.15.1 1.15.1 β€”
🟑 medium CVE-2026-44455 hono < 4.12.16 4.12.16 β€”
🟑 medium CVE-2026-44456 hono < 4.12.16 4.12.16 β€”
🟑 medium CVE-2026-44457 hono < 4.12.18 4.12.18 β€”
🟑 medium CVE-2026-44458 hono < 4.12.18 4.12.18 β€”
🟑 medium CVE-2026-42042 axios >= 1.0.0, < 1.15.1 1.15.1 β€”
🟑 medium CVE-2026-45409 idna < 3.15 3.15 β€”
🟑 medium CVE-2026-8723 qs >= 6.11.1, <= 6.15.1 6.15.2 β€”
🟑 medium CVE-2026-31241 mem0ai <= 1.0.0 β€” β€”
🟑 medium CVE-2026-31245 mem0ai <= 1.0.0 β€” β€”
🟑 medium CVE-2026-42039 axios >= 1.0.0, < 1.15.1 1.15.1 β€”
🟑 medium GHSA-4gg8-gxpx-9rph uv < 0.11.15 0.11.15 β€”
🟑 medium CVE-2026-48522 PyJWT >= 2.0.0, <= 2.12.1 2.13.0 β€”
🟑 medium CVE-2026-69207 hono < 4.12.34 4.12.34 β€”
🟑 medium CVE-2026-59881 aiohttp <= 3.14.1 3.14.2 β€”
🟑 medium CVE-2026-69243 aiohttp <= 3.14.1 3.14.2 β€”
🟑 medium GHSA-539m-9xh6-q6rr GitPython <= 3.1.56 3.1.57 β€”
🟑 medium GHSA-p538-c434-8v24 GitPython <= 3.1.55 3.1.56 β€”
🟑 medium CVE-2026-69153 postcss <= 8.5.22 8.5.23 β€”
🟑 medium CVE-2026-71554 h2 <= 4.4.0 4.4.1 β€”
🟑 medium CVE-2026-76217 GitPython <= 3.1.57 3.1.58 β€”
🟑 medium CVE-2026-71852 pypdf < 6.15.0 6.15.0 β€”
🟑 medium CVE-2026-71850 hono >= 3.8.0, < 4.12.34 4.12.34 β€”
🟑 medium CVE-2026-71870 pypdf < 6.15.0 6.15.0 β€”
🟑 medium GHSA-frvp-7c67-39w9 @hono/node-server < 1.19.15 1.19.15 β€”
🟑 medium CVE-2026-84309 pypdf < 6.16.0 6.16.0 β€”
🟑 medium CVE-2026-84311 pypdf < 6.16.1 6.16.1 β€”
🟑 medium CVE-2026-84310 pypdf < 6.16.1 6.16.1 β€”
🟑 medium CVE-2026-69248 cryptography >= 45.0.0, <= 48.0.0 49.0.0 β€”
🟑 medium CVE-2026-82398 pypdf < 6.15.0 6.15.0 β€”
🟑 medium GHSA-p498-v437-472g @humanfs/node < 0.16.8 0.16.8 β€”
🟑 medium CVE-2026-82417 qs >= 2.2.5, < 6.16.0 6.16.0 β€”
🟑 medium CVE-2026-84363 hono < 4.13.5 4.13.5 β€”
🟑 medium CVE-2026-84364 hono < 4.13.5 4.13.5 β€”
🟑 medium CVE-2026-84365 hono < 4.13.5 4.13.5 β€”
🟑 medium CVE-2026-78678 GitPython <= 3.1.58 3.1.59 β€”
🟑 medium CVE-2026-78679 GitPython <= 3.1.58 3.1.59 β€”
🟑 medium CVE-2026-12773 litellm < 1.84.0 1.84.0 β€”
🟑 medium CVE-2026-12795 litellm <= 1.82.2 β€” β€”
πŸ”΅ low CVE-2026-42040 axios >= 1.0.0, < 1.15.1 1.15.1 β€”
πŸ”΅ low CVE-2026-7597 mem0ai < 2.0.0b2 2.0.0b2 β€”
πŸ”΅ low CVE-2026-44459 hono < 4.12.18 4.12.18 β€”
πŸ”΅ low CVE-2026-48524 pyjwt >= 2.0.0, <= 2.12.1 2.13.0 β€”
πŸ”΅ low CVE-2026-71849 hono >= 4.7.0, < 4.12.34 4.12.34 β€”
πŸ”΅ low CVE-2026-12772 litellm <= 1.82.2 β€” β€”
πŸ”΅ low CVE-2026-12771 litellm <= 1.82.2 β€” β€”
πŸ”΅ low CVE-2026-12770 litellm <= 1.63.1 β€” β€”

Code Scanning Alerts

No open code scanning alerts.

Secret Scanning Alerts

No open secret scanning alerts.


Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions