Skip to content

[RHOAI 3.3] CVE-2026-63374: bump anyio 4.13.0 -> 4.14.2 in py312-rocm64-torch280, py312-cuda128-torch280 - #1078

Merged
sutaakar merged 1 commit into
red-hat-data-services:rhoai-3.3from
redhat-chai-bot:cve-2026-63374-anyio-rhoai-3.3
Oct 2, 2026
Merged

sutaakar merged 1 commit into
red-hat-data-services:rhoai-3.3from
redhat-chai-bot:cve-2026-63374-anyio-rhoai-3.3

Conversation

@redhat-chai-bot

Copy link
Copy Markdown

Summary

Bumps anyio from 4.13.0 to 4.14.2 in py312-rocm64-torch280 and py312-cuda128-torch280 runtime images to fix CVE-2026-63374 (TLS certificate spoofing via improper internationalized domain name encoding, CVSS 9.3 CRITICAL).

Changes

  • Updated Pipfile.lock pin for anyio to 4.14.2 using pipenv upgrade --lock-only anyio
  • Both affected runtime image variants updated in a single commit

Affected Jira Tickets

  • RHAI-3994 (py312-rocm64-torch280)
  • RHAI-3990 (py312-cuda128-torch280)

AI-generated. Review for accuracy.

Automated by scheduled task cve_worker (instructions: ship_help_bot/shared/instructions/scheduled/kubeflow_trainer_cve_worker.md, run: 5b451370e6df43948d8467bc6a5876cc, commit: 36ded0d32-dirty)

…8 and training-cuda128-torch28

Fixes CVE-2026-63374 (CVSS 9.3 CRITICAL) by upgrading anyio from
4.13.0 to 4.14.2 in the py312-rocm64-torch280 and py312-cuda128-torch280
runtime images.

Jira: RHAI-3994, RHAI-3990

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@sutaakar

sutaakar commented Oct 2, 2026

Copy link
Copy Markdown

/ok-to-test

@sutaakar
sutaakar merged commit 3307a8d into red-hat-data-services:rhoai-3.3 Oct 2, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants