mirror of
https://github.com/dograh-hq/dograh.git
synced 2026-06-07 07:55:16 +02:00
Closes three known advisories in python-multipart, all reachable from the FastAPI multipart form-parser used across the API (transcribe_audio, knowledge_base uploads, presigned upload flows): - GHSA-wp53-j4wj-2cfg (HIGH, CWE-22) — arbitrary file write via non-default configuration. Fixed in 0.0.22. - GHSA-pp6c-gr5w-3c5g (HIGH, CWE-400) — DoS via unbounded multipart part headers. Fixed in 0.0.27. - GHSA-mj87-hwqh-73pj (MOD, CWE-400) — DoS via large multipart preamble or epilogue. Fixed in 0.0.26. 0.0.27 is a patch-level bump within the same 0.0.x line, no API changes; fastapi==0.135.3 only requires python-multipart>=0.0.7 so the upper bound is unaffected. Detected by Aeon + osv-scanner. Co-authored-by: aeonframework <aeon@aaronjmars.com>
22 lines
401 B
Text
22 lines
401 B
Text
langfuse==3.9.3
|
|
fastapi==0.135.3
|
|
asyncpg==0.30.0
|
|
alembic==1.16.5
|
|
redis==5.3.1
|
|
uvicorn==0.35.0
|
|
aioboto3==15.1.0
|
|
arq==0.26.3
|
|
twilio==9.8.0
|
|
minio==7.2.16
|
|
alembic-postgresql-enum==1.8.0
|
|
python-multipart==0.0.27
|
|
sentry-sdk[fastapi]==2.38.0
|
|
sqlalchemy[asyncio]==2.0.43
|
|
msgpack==1.1.2
|
|
pgvector==0.4.2
|
|
bcrypt==5.0.0
|
|
email-validator==2.3.0
|
|
posthog==7.11.1
|
|
fastmcp==3.2.4
|
|
tuner-pipecat-sdk==0.2.0
|
|
PyNaCl==1.6.2
|