The latest released airbyte-cdk (7.25.1) and current main constrain setuptools to ^80.9.0, while CVE-2026-59890 is fixed in 83.0.0. Downstream connectors cannot override this because Poetry reports an unsatisfiable constraint.
Please widen/update the CDK constraint to include setuptools >=83.0.0 and publish a release so downstream lockfiles can remediate the vulnerability.
Trivy 0.74.0 reports this as MEDIUM with fixed version 83.0.0.
Internal Tracking: https://github.com/airbytehq/oncall/issues/13315
The latest released
airbyte-cdk(7.25.1) and currentmainconstrainsetuptoolsto^80.9.0, while CVE-2026-59890 is fixed in 83.0.0. Downstream connectors cannot override this because Poetry reports an unsatisfiable constraint.Please widen/update the CDK constraint to include
setuptools >=83.0.0and publish a release so downstream lockfiles can remediate the vulnerability.Trivy 0.74.0 reports this as MEDIUM with fixed version 83.0.0.
Internal Tracking: https://github.com/airbytehq/oncall/issues/13315