You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This should happen automatically as part of our next scheduled release (in April) when we'll update all our vendored dependencies to their latest releases.
Description
urllib3 versions 1.26.17 or below are affected by the security vulnerability CVE-2023-45803
GHSA-g4mx-q9vg-27p4
Is it possible to update urllib3 vendor bundle inside pip to 1.26.18 or above ?
Expected behavior
No response
pip version
main
Python version
main
OS
AIX, Linux
How to Reproduce
urllib3 version is 1.26.17 inside pip _vendor directory
Output
No response
Code of Conduct
The text was updated successfully, but these errors were encountered: