[PR #30976] fix(deps): security updates for pdfminer.six, authlib, werkzeug, aiohttp and others #33040

Closed
opened 2026-02-21 20:52:33 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/30976

State: closed
Merged: Yes


Important

  1. Make sure you have read our contribution guidelines
  2. Ensure there is an associated issue and you have been assigned to it
  3. Use the correct syntax to link this PR: Fixes #<issue number>.

Summary

Package Version CVE Fix Status
Authlib 1.6.5 CVE-2025-68158 fixed in 1.6.6
Werkzeug 3.1.4 CVE-2026-21860 fixed in 3.1.5
aiohttp 3.13.2 CVE-2025-69223 fixed in 3.13.3
fickling 0.1.6 CVE-2026-22606 fixed in 0.1.7
marshmallow 3.26.1 CVE-2025-68480 fixed in 3.26.2
pdfminer.six 20250506 CVE-2025-64512 fixed in 20251230
pypdf 6.4.0 CVE-2026-22690 fixed in 6.6.0
urllib3 2.6.0 CVE-2026-21441 fixed in 2.6.3

Screenshots

Before After
... ...

Checklist

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran make lint and make type-check (backend) and cd web && npx lint-staged (frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/30976 **State:** closed **Merged:** Yes --- > [!IMPORTANT] > > 1. Make sure you have read our [contribution guidelines](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) > 1. Ensure there is an associated issue and you have been assigned to it > 1. Use the correct syntax to link this PR: `Fixes #<issue number>`. ## Summary <!-- Please include a summary of the change and which issue is fixed. Please also include relevant motivation and context. List any dependencies that are required for this change. --> Package | Version | CVE | Fix Status -- | -- | -- | -- Authlib | 1.6.5 | CVE-2025-68158 | fixed in 1.6.6 Werkzeug |3.1.4|CVE-2026-21860 | fixed in 3.1.5 aiohttp |3.13.2|CVE-2025-69223 | fixed in 3.13.3 fickling |0.1.6|CVE-2026-22606 | fixed in 0.1.7 marshmallow |3.26.1|CVE-2025-68480 | fixed in 3.26.2 pdfminer.six |20250506|CVE-2025-64512 | fixed in 20251230 pypdf |6.4.0|CVE-2026-22690 | fixed in 6.6.0 urllib3 |2.6.0|CVE-2026-21441 | fixed in 2.6.3 ## Screenshots | Before | After | |--------|-------| | ... | ... | ## Checklist - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `make lint` and `make type-check` (backend) and `cd web && npx lint-staged` (frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:52:33 -05:00
yindo closed this issue 2026-02-21 20:52:33 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#33040