SECURITY: Update dependencies to fix 11 vulnerabilities (aiohttp, authlib, cryptography, fastapi, python-multipart)

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
This commit is contained in:
copilot-swe-agent[bot]
2026-02-01 13:00:31 +00:00
parent 0dc777bb7e
commit 439d1f2ec7
2 changed files with 14 additions and 6 deletions
+9 -1
View File
@@ -64,10 +64,18 @@ Security analysis completed on February 1, 2026 for the Multi-Tenant POP3 Forwar
### 6. Dependency Security ✅
- **Pinned Versions**: All dependencies use specific versions
- **Known Vulnerabilities**: No known vulnerabilities in dependencies
- **Security Patches**: All dependencies updated to patched versions
- **No Known Vulnerabilities**: All reported vulnerabilities fixed
- **Regular Updates**: Requirements can be easily updated
- **Minimal Dependencies**: Only necessary packages included
**Recent Security Updates (2026-02-01):**
- `aiohttp`: 3.9.1 → 3.13.3 (Fixed zip bomb, DoS, directory traversal)
- `authlib`: 1.3.0 → 1.6.5 (Fixed algorithm confusion, DoS, JWT issues)
- `cryptography`: 42.0.0 → 42.0.4 (Fixed NULL pointer dereference)
- `fastapi`: 0.109.0 → 0.109.1 (Fixed ReDoS vulnerability)
- `python-multipart`: 0.0.6 → 0.0.22 (Fixed arbitrary file write, DoS, ReDoS)
**Implementation**: `backend/requirements.txt`
## Security Best Practices Applied