Skip to content

fix: bump cryptography to ~=50.0 for CVE-2026-69247 - #707

Merged
gjtorikian merged 1 commit into
mainfrom
fix/bump-cryptography-50
Aug 4, 2026
Merged

fix: bump cryptography to ~=50.0 for CVE-2026-69247#707
gjtorikian merged 1 commit into
mainfrom
fix/bump-cryptography-50

Conversation

@gjtorikian

@gjtorikian gjtorikian commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

Summary

Release-As: 10.1.1

Force a patch release (10.1.1) to ship the cryptography 50.0 upgrade
that landed in #706 as a chore commit, which release-please does not
release on its own.

CVE-2026-69247 / GHSA-g6cj-pr64-35w5: PKCS#7 EnvelopedData decryption
exposes a Bleichenbacher oracle. Affects cryptography >=44.0.0,<50.0.0,
fixed in 50.0.0.

Release-As: 10.1.1
@gjtorikian
gjtorikian merged commit d82226c into main Aug 4, 2026
12 checks passed
@gjtorikian
gjtorikian deleted the fix/bump-cryptography-50 branch August 4, 2026 15:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant