Skip to content

πŸ”’ Security Alerts β€” IBM/ibmdotcom-tutorialsΒ #136

Description

@security-ops-bot

πŸ”’ Security Alerts β€” IBM/ibmdotcom-tutorials

Action required: Remediate the alerts listed below before their SLA deadline.
This issue will be closed automatically once all alerts are resolved.

SLA policy: critical = 7 days, high = 30 days, medium = 90 days, low = no deadline.
Alerts at or above medium severity will trigger a warning comment before the deadline and
repo archiving if unresolved. Low-severity alerts are tracked here for visibility only β€”
they will never trigger warnings or archiving.

πŸ’‘ Tip: To have Dependabot automatically open fix PRs for dependency alerts, enable
Dependabot security updates in your repo settings:
Settings β†’ Advanced Security β†’ Dependabot security updates β†’ Enable.

πŸ“– New to this issue? See the Security Issue Guide for a full explanation of what this issue means and what you need to do.

Attention: @thinkscientist

Dependabot Alerts

Severity CVE/GHSA Package Affected Patched Fix PR
πŸ”΄ critical CVE-2025-68664 langchain-core < 0.3.81 0.3.81 β€”
πŸ”΄ critical CVE-2026-35030 litellm < 1.83.0 1.83.0 β€”
πŸ”΄ critical CVE-2026-45833 chromadb >= 0.4.17, <= 1.5.9 β€” β€”
πŸ”΄ critical CVE-2026-37004 litellm < 1.83.7 1.83.7 β€”
πŸ”΄ critical CVE-2026-78676 GitPython <= 3.1.58 3.1.59 β€”
🟠 high CVE-2025-64439 langgraph-checkpoint < 3.0.0 3.0.0 β€”
🟠 high CVE-2025-65106 langchain-core <= 0.3.79 0.3.80 β€”
🟠 high CVE-2025-66418 urllib3 >= 1.24, < 2.6.0 2.6.0 β€”
🟠 high CVE-2025-66471 urllib3 >= 1.0, < 2.6.0 2.6.0 β€”
🟠 high CVE-2026-21441 urllib3 >= 1.22, < 2.6.3 2.6.3 β€”
🟠 high CVE-2025-67221 orjson < 3.11.6 3.11.6 β€”
🟠 high CVE-2026-34070 langchain-core < 1.2.22 1.2.22 β€”
🟠 high CVE-2025-62727 starlette >= 0.39.0, <= 0.49.0 0.49.1 β€”
🟠 high CVE-2025-66416 mcp < 1.23.0 1.23.0 β€”
🟠 high CVE-2025-69223 aiohttp <= 3.13.2 3.13.3 β€”
🟠 high CVE-2026-23490 pyasn1 = 0.6.1 0.6.2 β€”
🟠 high CVE-2026-24486 python-multipart < 0.0.22 0.0.22 β€”
🟠 high CVE-2026-0994 protobuf >= 6.30.0rc1, <= 6.33.4 6.33.5 β€”
🟠 high CVE-2026-25580 pydantic-ai >= 0.0.26, < 1.56.0 1.56.0 β€”
🟠 high CVE-2026-30922 pyasn1 <= 0.6.2 0.6.3 β€”
🟠 high CVE-2026-35029 litellm < 1.83.0 1.83.0 β€”
🟠 high GHSA-69x8-hrgq-fjj8 litellm < 1.83.0 1.83.0 β€”
🟠 high CVE-2026-47101 litellm < 1.83.14 1.83.14 β€”
🟠 high CVE-2026-47102 litellm < 1.83.10 1.83.10 β€”
🟠 high CVE-2026-49477 soupsieve <= 2.8.3 2.8.4 β€”
🟠 high CVE-2026-49476 soupsieve <= 2.8.3 2.8.4 β€”
🟠 high GHSA-xf7x-x43h-rpqh json-repair < 0.60.1 0.60.1 β€”
🟠 high CVE-2026-54060 pillow < 12.3.0 12.3.0 β€”
🟠 high CVE-2026-54058 pillow < 12.3.0 12.3.0 β€”
🟠 high CVE-2026-54059 pillow < 12.3.0 12.3.0 β€”
🟠 high CVE-2026-55380 pillow < 12.3.0 12.3.0 β€”
🟠 high CVE-2026-55379 pillow < 12.3.0 12.3.0 β€”
🟠 high CVE-2026-59197 Pillow < 12.3.0 12.3.0 β€”
🟠 high CVE-2026-59199 Pillow < 12.3.0 12.3.0 β€”
🟠 high CVE-2026-59200 Pillow >= 5.1.0, < 12.3.0 12.3.0 β€”
🟠 high CVE-2026-59204 pillow >= 8.2.0, < 12.3.0 12.3.0 β€”
🟠 high CVE-2026-59205 pillow < 12.3.0 12.3.0 β€”
🟠 high CVE-2026-13149 brace-expansion < 1.1.16 1.1.16 β€”
🟠 high CVE-2026-59869 js-yaml >= 4.0.0, < 4.3.0 4.3.0 β€”
🟠 high CVE-2026-59885 pyasn1 <= 0.6.3 0.6.4 β€”
🟠 high CVE-2026-59886 pyasn1 <= 0.6.3 0.6.4 β€”
🟠 high CVE-2026-13676 fast-uri >= 3.0.0, < 3.1.3 3.1.3 β€”
🟠 high GHSA-3rp5-jjmw-4wv2 gitpython <= 3.1.52 3.1.53 β€”
🟠 high GHSA-6p8h-3wgx-97gf GitPython <= 3.1.53 3.1.54 β€”
🟠 high GHSA-fjr4-x663-mwxc GitPython <= 3.1.53 3.1.54 β€”
🟠 high GHSA-r9mr-m37c-5fr3 GitPython <= 3.1.53 3.1.54 β€”
🟠 high GHSA-94p4-4cq8-9g67 GitPython <= 3.1.53 3.1.55 β€”
🟠 high CVE-2026-45623 postcss <= 8.5.11 8.5.12 β€”
🟠 high CVE-2026-73646 postcss <= 8.5.17 8.5.18 β€”
🟠 high CVE-2026-59884 pyasn1 < 0.6.4 0.6.4 β€”
🟠 high CVE-2026-69244 aiohttp <= 3.14.2 3.14.3 β€”
🟠 high GHSA-3f7w-8rr8-f37f GitPython <= 3.1.56 3.1.57 β€”
🟠 high CVE-2026-69247 cryptography >= 44.0.0, < 50.0.0 50.0.0 β€”
🟠 high CVE-2026-18446 fast-uri >= 3.0.0, < 3.1.5 3.1.5 β€”
🟠 high GHSA-5p4m-2wfm-xmqj js-yaml >= 4.0.0, < 4.3.1 4.3.1 β€”
🟠 high CVE-2026-76219 GitPython <= 3.1.57 3.1.58 β€”
🟠 high CVE-2026-76218 GitPython <= 3.1.57 3.1.58 β€”
🟠 high CVE-2026-76220 GitPython <= 3.1.57 3.1.58 β€”
🟠 high GHSA-jm78-9fvv-mhgr GitPython <= 3.1.57 3.1.58 β€”
🟠 high CVE-2026-76222 GitPython <= 3.1.57 3.1.58 β€”
🟠 high CVE-2026-6322 fast-uri >= 3.0.0, <= 3.1.1 3.1.2 β€”
🟠 high CVE-2026-6321 fast-uri >= 3.0.0, <= 3.1.0 3.1.1 β€”
🟠 high CVE-2026-45831 chromadb >= 0.5.0, <= 1.5.9 β€” β€”
🟠 high CVE-2026-45830 chromadb >= 0.4.17, <= 1.5.9 β€” β€”
🟠 high CVE-2026-73088 browserslist <= 4.28.6 4.28.7 β€”
🟠 high CVE-2026-73086 nanoid < 3.3.12 3.3.12 β€”
🟠 high CVE-2026-76172 fast-uri >= 3.0.0, < 3.1.6 3.1.6 β€”
🟠 high CVE-2026-75975 fast-uri >= 3.0.0, < 3.1.6 3.1.6 β€”
🟠 high CVE-2026-62240 crewai-tools < 1.15.1 1.15.1 β€”
🟠 high CVE-2026-69249 cryptography >= 42.0.0, <= 48.0.0 49.0.0 β€”
🟠 high CVE-2026-78677 GitPython <= 3.1.58 3.1.59 β€”
🟠 high CVE-2026-78675 GitPython <= 3.1.58 3.1.59 β€”
🟠 high CVE-2026-84375 js-yaml >= 4.0.0, < 4.3.2 4.3.2 β€”
🟑 medium CVE-2024-47081 requests < 2.32.4 2.32.4 β€”
🟑 medium CVE-2026-27794 langgraph-checkpoint < 4.0.0 4.0.0 β€”
🟑 medium CVE-2026-28277 langgraph <= 1.0.9 1.0.10 β€”
🟑 medium CVE-2026-25645 requests < 2.33.0 2.33.0 β€”
🟑 medium CVE-2026-40087 langchain-core < 0.3.83 0.3.84 β€”
🟑 medium CVE-2025-71176 pytest < 9.0.3 9.0.3 β€”
🟑 medium CVE-2025-68146 filelock < 3.20.1 3.20.1 β€”
🟑 medium CVE-2025-69227 aiohttp <= 3.13.2 3.13.3 β€”
🟑 medium CVE-2025-69228 aiohttp <= 3.13.2 3.13.3 β€”
🟑 medium CVE-2025-69229 aiohttp <= 3.13.2 3.13.3 β€”
🟑 medium CVE-2026-22701 filelock < 3.20.3 3.20.3 β€”
🟑 medium CVE-2026-22815 aiohttp <= 3.13.3 3.13.4 β€”
🟑 medium CVE-2026-34515 aiohttp <= 3.13.3 3.13.4 β€”
🟑 medium CVE-2026-34516 aiohttp <= 3.13.3 3.13.4 β€”
🟑 medium CVE-2026-34525 aiohttp <= 3.13.3 3.13.4 β€”
🟑 medium CVE-2025-55197 pypdf < 6.0.0 6.0.0 β€”
🟑 medium CVE-2025-57804 h2 < 4.3.0 4.3.0 β€”
🟑 medium CVE-2025-62707 pypdf < 6.1.3 6.1.3 β€”
🟑 medium CVE-2025-62708 pypdf < 6.1.3 6.1.3 β€”
🟑 medium GHSA-pqhf-p39g-3x64 uv <= 0.9.5 0.9.6 β€”
🟑 medium CVE-2025-66019 pypdf < 6.4.0 6.4.0 β€”
🟑 medium CVE-2026-48775 langgraph-checkpoint < 4.1.1 4.1.1 β€”
🟑 medium CVE-2026-48776 langgraph-sdk < 0.3.15 0.3.15 β€”
🟑 medium CVE-2026-53550 js-yaml >= 4.0.0, <= 4.1.1 4.2.0 β€”
🟑 medium CVE-2026-54651 pypdf < 6.13.1 6.13.1 β€”
🟑 medium CVE-2026-28684 python-dotenv < 1.2.2 1.2.2 β€”
🟑 medium CVE-2026-48990 joserfc >= 1.3.4, < 1.6.7 1.6.7 β€”
🟑 medium CVE-2026-55798 Pillow < 12.3.0 12.3.0 β€”
🟑 medium CVE-2026-59203 pillow >= 12.0.0, < 12.3.0 12.3.0 β€”
🟑 medium CVE-2026-59198 Pillow >= 5.2.0, < 12.3.0 12.3.0 β€”
🟑 medium CVE-2026-67312 axios >= 1.0.0, < 1.18.0 1.18.0 β€”
🟑 medium CVE-2026-67313 axios >= 1.0.0, < 1.18.0 1.18.0 β€”
🟑 medium CVE-2026-67316 axios >= 1.0.0, < 1.18.0 1.18.0 β€”
🟑 medium CVE-2026-67317 axios >= 1.7.0, < 1.18.0 1.18.0 β€”
🟑 medium CVE-2026-67318 axios >= 1.13.0, < 1.18.0 1.18.0 β€”
🟑 medium CVE-2026-67319 axios >= 1.0.0, < 1.18.0 1.18.0 β€”
🟑 medium CVE-2026-59890 setuptools < 83.0.0 83.0.0 β€”
🟑 medium CVE-2026-59897 hono >= 4.3.3, < 4.12.27 4.12.27 β€”
🟑 medium CVE-2026-59895 hono >= 4.0.0, < 4.12.27 4.12.27 β€”
🟑 medium CVE-2026-48522 PyJWT >= 2.0.0, <= 2.12.1 2.13.0 β€”
🟑 medium CVE-2026-69207 hono < 4.12.34 4.12.34 β€”
🟑 medium CVE-2026-59881 aiohttp <= 3.14.1 3.14.2 β€”
🟑 medium CVE-2026-69243 aiohttp <= 3.14.1 3.14.2 β€”
🟑 medium GHSA-539m-9xh6-q6rr GitPython <= 3.1.56 3.1.57 β€”
🟑 medium GHSA-p538-c434-8v24 GitPython <= 3.1.55 3.1.56 β€”
🟑 medium CVE-2026-69153 postcss <= 8.5.22 8.5.23 β€”
🟑 medium CVE-2026-71554 h2 <= 4.4.0 4.4.1 β€”
🟑 medium CVE-2026-76217 GitPython <= 3.1.57 3.1.58 β€”
🟑 medium CVE-2026-71852 pypdf < 6.15.0 6.15.0 β€”
🟑 medium CVE-2026-71850 hono >= 3.8.0, < 4.12.34 4.12.34 β€”
🟑 medium CVE-2026-71870 pypdf < 6.15.0 6.15.0 β€”
🟑 medium GHSA-frvp-7c67-39w9 @hono/node-server < 1.19.15 1.19.15 β€”
🟑 medium CVE-2026-84309 pypdf < 6.16.0 6.16.0 β€”
🟑 medium CVE-2026-84311 pypdf < 6.16.1 6.16.1 β€”
🟑 medium CVE-2026-84310 pypdf < 6.16.1 6.16.1 β€”
🟑 medium CVE-2026-69248 cryptography >= 45.0.0, <= 48.0.0 49.0.0 β€”
🟑 medium CVE-2026-82398 pypdf < 6.15.0 6.15.0 β€”
🟑 medium GHSA-p498-v437-472g @humanfs/node < 0.16.8 0.16.8 β€”
🟑 medium CVE-2026-82417 qs >= 2.2.5, < 6.16.0 6.16.0 β€”
🟑 medium CVE-2026-84363 hono < 4.13.5 4.13.5 β€”
🟑 medium CVE-2026-84364 hono < 4.13.5 4.13.5 β€”
🟑 medium CVE-2026-84365 hono < 4.13.5 4.13.5 β€”
🟑 medium CVE-2026-78678 GitPython <= 3.1.58 3.1.59 β€”
🟑 medium CVE-2026-78679 GitPython <= 3.1.58 3.1.59 β€”
🟑 medium CVE-2026-12773 litellm < 1.84.0 1.84.0 β€”
🟑 medium CVE-2026-12795 litellm <= 1.82.2 β€” β€”
πŸ”΅ low CVE-2026-26013 langchain-core < 1.2.11 1.2.11 β€”
πŸ”΅ low CVE-2025-69224 aiohttp <= 3.13.2 3.13.3 β€”
πŸ”΅ low CVE-2025-69225 aiohttp <= 3.13.2 3.13.3 β€”
πŸ”΅ low CVE-2025-69226 aiohttp <= 3.13.2 3.13.3 β€”
πŸ”΅ low CVE-2025-69230 aiohttp <= 3.13.2 3.13.3 β€”
πŸ”΅ low CVE-2026-4539 Pygments < 2.20.0 2.20.0 β€”
πŸ”΅ low CVE-2026-34513 aiohttp <= 3.13.3 3.13.4 β€”
πŸ”΅ low CVE-2026-34514 aiohttp <= 3.13.3 3.13.4 β€”
πŸ”΅ low CVE-2026-34517 aiohttp <= 3.13.3 3.13.4 β€”
πŸ”΅ low CVE-2026-34518 aiohttp <= 3.13.3 3.13.4 β€”
πŸ”΅ low CVE-2026-34519 aiohttp <= 3.13.3 3.13.4 β€”
πŸ”΅ low CVE-2026-34520 aiohttp <= 3.13.3 3.13.4 β€”
πŸ”΅ low GHSA-w476-p2h3-79g9 uv <= 0.9.4 0.9.5 β€”
πŸ”΅ low CVE-2026-10812 gptcache <= 0.1.44 β€” β€”
πŸ”΅ low CVE-2026-12590 body-parser >= 2.0.0, < 2.3.0 2.3.0 β€”
πŸ”΅ low CVE-2026-48524 pyjwt >= 2.0.0, <= 2.12.1 2.13.0 β€”
πŸ”΅ low CVE-2026-71849 hono >= 4.7.0, < 4.12.34 4.12.34 β€”
πŸ”΅ low CVE-2026-12772 litellm <= 1.82.2 β€” β€”
πŸ”΅ low CVE-2026-12771 litellm <= 1.82.2 β€” β€”
πŸ”΅ low CVE-2026-12770 litellm <= 1.63.1 β€” β€”
πŸ”΅ low CVE-2026-12796 litellm <= 1.82.2 β€” β€”
πŸ”΅ low CVE-2026-12797 litellm <= 1.82.5 β€” β€”
πŸ”΅ low CVE-2026-12798 litellm <= 1.82.2 β€” β€”
πŸ”΅ low CVE-2026-12799 litellm <= 1.82.2 β€” β€”

Code Scanning Alerts

No open code scanning alerts.

Secret Scanning Alerts

No open secret scanning alerts.


Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions