fix: upgrade pyasn1 to address CVE-2026-30922#3346
Conversation
pyasn1 0.5.1 is affected by CVE-2026-30922. Upgrading the version pin to >=0.6.3 which contains the fix. Detected by: pip-audit
|
/review |
There was a problem hiding this comment.
Copilot wasn't able to review any files in this pull request.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
jlklos
left a comment
There was a problem hiding this comment.
Tested and ran a test operation after launching Caldera server. No issues detected.
There was a problem hiding this comment.
Copilot wasn't able to review any files in this pull request.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
jlklos
left a comment
There was a problem hiding this comment.
Updated to pin version to 0.6.3.
|
Azure Pipelines: 1 pipeline(s) were filtered out due to trigger conditions. |
|
❌ The last analysis has failed. |
|
|
❌ The last analysis has failed. |
uruwhy
left a comment
There was a problem hiding this comment.
changelogs from the package don't seem to indicate any breaking changes



Summary
pyasn1from~=0.5.1to>=0.6.3to fix CVE-2026-30922CVE Details
pip-auditTest plan
pip install -r requirements.txtsucceeds