aliyun / aliyun/alibabacloud-python-sdk

CVE-2026-34180 - cryptography version < 48.0.1

Open
#48 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
139
Forks
38
PR merge metrics
No merged PRs in 30d

Description

The library cryptography version 46.0.7 as a dependency of alibabacloud-status20200117 is Vulnerable to CVE-2026-34180

Other packages:

  • alibabacloud-tea-openai version 0.4.4 also has a dependency to the vulnerable package
  • alibabacloud-sts-20150401 version 1.20. also has a dependency to the vulnerable package
    The versions of OpenSSL included in wheels prior to cryptograph 48.01 are vulnerable to a security issue.

https://osv.dev/vulnerability/GHSA-537c-gmf6-5ccf

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review the dependency declarations for alibabacloud-status20200117, alibabacloud-tea-openai, and alibabacloud-sts-20150401, starting with how each resolves cryptography 46.0.7. Verify that each package no longer selects a cryptography version below 48.0.1 and that the repository's available checks pass.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
cryptography, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.