Update vulnerable dependencies (GitPython, urllib3) in python/requirements.txt
envgap__o3de__o3de-19913
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
87fedfb5923427072a50103d261b12752884e881- Manifest
python/requirements.txt- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
o3de/o3de #19913 · read the original issue
**Describe the bug** Outdated dependencies `gitpython` and `urllib3` in `python/requirements.txt` pose security risks to the build environment. Specifically, GitPython 3.1.41 allows Remote Code Execution (RCE) via a newline injection bypass, while urllib3 1.26.9 is vulnerable to decompression-bomb safeguard bypass (DoS) and proxy-authorization header leakage. **Assets required** None. **Steps to reproduce** Security scanner logs (from tools like Trivy or pip-audit) show active vulnerabilities when analyzing the project's Python dependencies. Running a scan directly on the `python/requirements.txt` manifest highlights these issues. **Expected behavior** Pinned package versions need to be upgraded to secure releases to comply with security standards. **Actual behavior** Current requirements file contains old versions: - `gitpython==3.1.41` (CVE-2026-42215 newline injection bypass) - `urllib3==1.26.9` (CVE-2026-21441 decompression bomb bypass, CVE-2024-37891 proxy-authorization leak) **Found in Branch** development **Commit ID from o3de/o3de Repository** HEAD **Desktop/Device** Build and development hosts (Linux, macOS, Windows) **Additional context** Upgrading to `gitpython>=3.1.50` and `urllib3>=1.26.19` (or `2.7.0` if compatibility permits) resolves these issues. Generating a new lockfile with valid hashes using internal pip-compile tools will ensure dependency integrity.
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]