← All tasks
pythono3de/o3de #19913Not a task: already works

Update vulnerable dependencies (GitPython, urllib3) in python/requirements.txt

envgap__o3de__o3de-19913

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
87fedfb5923427072a50103d261b12752884e881
Manifest
python/requirements.txt
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

o3de/o3de #19913 · read the original issue
**Describe the bug**
Outdated dependencies `gitpython` and `urllib3` in `python/requirements.txt` pose security risks to the build environment. Specifically, GitPython 3.1.41 allows Remote Code Execution (RCE) via a newline injection bypass, while urllib3 1.26.9 is vulnerable to decompression-bomb safeguard bypass (DoS) and proxy-authorization header leakage.

**Assets required**
None.

**Steps to reproduce**
Security scanner logs (from tools like Trivy or pip-audit) show active vulnerabilities when analyzing the project's Python dependencies. Running a scan directly on the `python/requirements.txt` manifest highlights these issues.

**Expected behavior**
Pinned package versions need to be upgraded to secure releases to comply with security standards.

**Actual behavior**
Current requirements file contains old versions:
- `gitpython==3.1.41` (CVE-2026-42215 newline injection bypass)
- `urllib3==1.26.9` (CVE-2026-21441 decompression bomb bypass, CVE-2024-37891 proxy-authorization leak)

**Found in Branch**
development

**Commit ID from o3de/o3de Repository**
HEAD

**Desktop/Device**
Build and development hosts (Linux, macOS, Windows)

**Additional context**
Upgrading to `gitpython>=3.1.50` and `urllib3>=1.26.19` (or `2.7.0` if compatibility permits) resolves these issues. Generating a new lockfile with valid hashes using internal pip-compile tools will ensure dependency integrity.
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]