Skip to content

Conversation

@kstribrnAmzn
Copy link
Member

@kstribrnAmzn kstribrnAmzn commented Dec 23, 2025

Description of changes:
This dependency update prevents a
malicious compression exploit as
documented in CVE-2025-66418.

  • Testing: *
    Relying on the CI step test-link-verifier to handle testing. If tests pass then I'd consider this good enough.

Issue #, if available:

By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.

This dependency update prevents a
malicious compression exploit as
documented in CVE-2025-66418.

https://nvd.nist.gov/vuln/detail/CVE-2025-66418
@kstribrnAmzn
Copy link
Member Author

Note - the link verifier is failing due to microchip's URL returning a 403. This can be fixed in a separate PR as I don't think this is related to the urllib3 dpeendency update.

@kstribrnAmzn
Copy link
Member Author

Merging this in to reduce the risk from the CVE. I will continue to debug the microchip link verification issue if it persists.

@kstribrnAmzn kstribrnAmzn merged commit 1de06de into FreeRTOS:main Jan 12, 2026
126 of 132 checks passed
@kstribrnAmzn kstribrnAmzn deleted the urllibFix branch January 12, 2026 15:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants