Skip to content

Release Python SDK GCP KMS Storage v1.1.1 - #1068

Draft
stas-schaller wants to merge 3 commits into
masterfrom
release/storage/python/gcp-kms/v1.1.1
Draft

stas-schaller wants to merge 3 commits into
masterfrom
release/storage/python/gcp-kms/v1.1.1

Conversation

@stas-schaller

@stas-schaller stas-schaller commented Jul 24, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

CVE hotfix: upgrades urllib3 to 2.7.0 and raises the Python floor to 3.10.

  • CVE-2026-44431 (urllib3, CVSS High): sensitive headers forwarded across origins on redirect. Fixed by upgrading urllib3 to 2.7.0.
  • requires-python raised to >=3.10 — urllib3 2.7.0 dropped Python 3.9 support (Python 3.9 EOL Oct 2025).
  • Python 3.9 classifier removed from pyproject.toml.
  • requirements.txt regenerated via uv pip compile --python-version 3.10 --universal.

KSM-1021

Breaking Changes

None for supported Python versions. Python 3.9 is EOL and was already dropped by urllib3 2.7.0.

Bump requires-python to >=3.10 (urllib3 2.7.0 drops Python 3.9 support),
remove Python 3.9 classifier, and regenerate requirements.txt. Version 1.1.1.
urllib3 2.7.0 dropped Python 3.9 (KSM-1021 bumped requires-python to
>=3.10), but the test and publish workflows still ran a 3.9 matrix leg,
which failed to resolve deps and canceled the rest of the matrix via
fail-fast. Publish job also built/verified the wheel on 3.9, which pip
would refuse to install once requires-python excludes it.
…-1240)

cryptography>=50.0.0 fixes four advisories the 48.0.0 pin left open:
GHSA-537c-gmf6-5ccf (vulnerable OpenSSL in wheels, fixed 48.0.1),
GHSA-jwv3-5hgf-82ww / CVE-2026-69249 (exponential path-building via
duplicate self-signed intermediates, fixed 49.0.0), GHSA-m2h6-j472-rp4c /
CVE-2026-69248 (wildcard DNS name verifier escape, fixed 49.0.0), and
GHSA-g6cj-pr64-35w5 / CVE-2026-69247 (PKCS#7 EnvelopedData Bleichenbacher
oracle, fixed 50.0.0).

pyasn1 was only a transitive dependency via google-auth, pinned at
0.6.3 with no floor of our own. Added it directly at >=0.6.4, fixing
GHSA-m4p7-r5rc-7g4j / CVE-2026-59884, GHSA-hm4w-wwcw-mr6r / CVE-2026-59886,
and GHSA-8ppf-4f7h-5ppj / CVE-2026-59885 (BER/CER/DER decoder DoS,
uncontrolled resource consumption, and quadratic-complexity OID
processing).

Regenerated requirements.txt via uv pip compile per project convention.
This does not change requires-python; both packages already resolve on
Python 3.10, the floor this branch already raised for the urllib3 fix.

KSM-1240
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedpypi/​pyasn1@​0.6.3 ⏵ 0.6.4100100 +31100100100

View full report

@mgallego-keeper mgallego-keeper changed the title fix(gcp-kms): upgrade urllib3 to 2.7.0 to fix CVE-2026-44431 (KSM-1021) Release Python SDK GCP KMS Storage v1.1.1 Sep 16, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants