Skip to content

fix: #CVE-2026-27962 #CVE-2026-32871 #CVE-2026-63374 #CVE-2026-102268 - #626

Merged
DhavalRepo18 merged 1 commit into
mainfrom
fix/critical-cves
Oct 6, 2026
Merged

DhavalRepo18 merged 1 commit into
mainfrom
fix/critical-cves

Conversation

@ShuxinLin

Copy link
Copy Markdown
Collaborator

Description

Fixes the four critical Dependabot alerts that IBM's security bot is tracking in #580. Three were due 2026-10-06; CVE-2026-102268 is due 2026-10-09. The alert IDs are in the PR title because the bot checks titles to count an alert as being fixed.

Alert Package Before After Fixed in
CVE-2026-27962 authlib (via fastmcp) 1.6.8 1.8.0 ≥ 1.6.9
CVE-2026-32871 fastmcp 2.14.5 3.4.8 ≥ 3.2.0
CVE-2026-63374 anyio 4.12.1 4.15.1 ≥ 4.14.2
CVE-2026-102268 pyjwt (via mcp) 2.11.0 2.15.1 ≥ 2.14.0

pyproject.toml:

  • Raises the minimum versions of fastmcp (≥ 3.2.0) and anyio (≥ 4.14.2).
  • Adds [tool.uv] constraint-dependencies for authlib and pyjwt, so a future re-lock can't fall back to a vulnerable version.

uv.lock was re-locked with --upgrade-package for only these four packages. The new versions also need:

  • fastmcp 2 → 3 (major). Low risk: no code imports the fastmcp package. The servers use mcp.server.fastmcp, which ships inside the mcp SDK, and mcp stays at 1.26.0.
  • starlette 0.52 → 1.7 (major), required by fastmcp 3. Every server runs over stdio, so starlette's HTTP code isn't used at runtime.
  • python-multipart 0.0.22 → 0.0.32. fastmcp 3 also no longer needs pydocket, redis, fakeredis or lupa, so they were removed from the lock.

Testing

  • uv run pytest src/ -k "not integration": 696 passed, 8 failed, 3 skipped. The same 8 tests also fail on unmodified main: 6 in test_static_json_scorer.py, and 2 in test_file_exporter.py that can't import google.protobuf.
  • Started all six servers (iot, utilities, fmsr, wo, vibration, tsfm) over stdio, initialised a client session, and listed their tools. All worked.

Changes

  • Dependency update (uv lock)
  • Documentation / Tutorial update
  • Refactoring (no logic change)

Checklist

  • I have signed off my commits (DCO).

Clears the critical Dependabot alerts tracked in #580:

- CVE-2026-27962 authlib 1.6.8 -> 1.8.0 (via fastmcp)
- CVE-2026-32871 fastmcp 2.14.5 -> 3.4.8
- CVE-2026-63374 anyio 4.12.1 -> 4.15.1
- CVE-2026-102268 pyjwt 2.11.0 -> 2.15.1 (via mcp)

Raises the fastmcp and anyio floors in pyproject.toml, and adds uv
constraint-dependencies for authlib and pyjwt so a re-lock can't fall
back to a vulnerable version. fastmcp 3 also pulls starlette
0.52 -> 1.7.

Signed-off-by: Shuxin Lin <linshuhsin@gmail.com>
@ShuxinLin
ShuxinLin requested a review from DhavalRepo18 October 6, 2026 20:32
@DhavalRepo18
DhavalRepo18 merged commit de07574 into main Oct 6, 2026
8 checks passed
@ShuxinLin
ShuxinLin deleted the fix/critical-cves branch October 6, 2026 22:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants