Commit 43b033d
committed
Bump idna to 3.18 to fix a security advisory
Fixes dependabot alert #25:
- GHSA-65pc-fj4g-8rjx (CVE-2026-45409): specially crafted input to
idna.encode() bypasses the CVE-2024-3651 fix, allowing excessive
resource consumption
idna is a transitive dependency of requests.1 parent 0b0d945 commit 43b033d
1 file changed
Lines changed: 7 additions & 4 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments