Skip to content

Outdated cryptography dependency contains CVE-2026-26007 #956

Description

Hello,

I noticed we are pinned the following for cryptography version which has CVE-2026-26007:

cryptography = ">=44.0.0,<45.0.0"  # Constrained as transitive dependency due to a bug in newer versions

Is there a plan to update this to a newer version?

Thanks,
Yong


Internal Tracking: https://github.com/airbytehq/oncall/issues/11849

Metadata

Metadata

Assignees

No one assigned

    Labels

    communityPRs and issues from community contributors

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions