Skip to content

[RHOAI 3.4] CVE-2026-63374: bump anyio 4.13.0 -> 4.15.1 in py311 runtime images - #1073

Merged
sutaakar merged 1 commit into
red-hat-data-services:rhoai-3.4from
redhat-chai-bot:cve-2026-63374-anyio-py311-rhoai-3.4
Oct 2, 2026
Merged

sutaakar merged 1 commit into
red-hat-data-services:rhoai-3.4from
redhat-chai-bot:cve-2026-63374-anyio-py311-rhoai-3.4

Conversation

@redhat-chai-bot

Copy link
Copy Markdown

Summary

Bumps anyio from 4.13.0 to 4.15.1 in all py311 runtime training images to address CVE-2026-63374 (AnyIO TLS certificate spoofing via improper IDNA encoding). Fix version is >=4.14.2.

Changes

Ran pipenv upgrade --lock-only anyio in each affected image directory:

  • images/runtime/training/py311-cuda124-torch251/
  • images/runtime/training/py311-cuda121-torch241/
  • images/runtime/training/py311-rocm62-torch251/
  • images/runtime/training/py311-rocm62-torch241/

Package changes

  • anyio: 4.13.0 → 4.15.1
  • idna: 3.18 → 3.20 (direct dep of anyio)
  • typing-extensions: 4.15.0 → 4.16.0 (direct dep of anyio)

CVE Reference

Related Jira tickets

  • RHAI-4019, RHAI-4018, RHAI-4017, RHAI-4016 (rhoai-3.4 py311 runtime)

AI-generated. Review for accuracy.

Automated by scheduled task cve_worker (instructions: ship_help_bot/shared/instructions/scheduled/kubeflow_trainer_cve_worker.md, run: eb1cc4da61f2447a953a465288a17515, commit: 7fabe63f0-dirty)

Upgrade anyio from 4.13.0 to 4.15.1 (>=4.14.2) in all four py311
runtime training images to remediate CVE-2026-63374.

Updated images:
- py311-cuda124-torch251
- py311-cuda121-torch241
- py311-rocm62-torch251
- py311-rocm62-torch241

Transitive dependency bumps (direct deps of anyio):
- idna: 3.18 -> 3.20
- typing-extensions: 4.15.0 -> 4.16.0
@redhat-chai-bot
redhat-chai-bot force-pushed the cve-2026-63374-anyio-py311-rhoai-3.4 branch from 9907e3f to da9fb9c Compare October 2, 2026 13:34
@sutaakar
sutaakar merged commit 0183ec3 into red-hat-data-services:rhoai-3.4 Oct 2, 2026
2 of 3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants