package/python-urllib3: security bump to version 1.26.6
authorFabrice Fontaine <fontaine.fabrice@gmail.com>
Mon, 5 Jul 2021 21:14:53 +0000 (23:14 +0200)
committerThomas Petazzoni <thomas.petazzoni@bootlin.com>
Fri, 16 Jul 2021 21:30:26 +0000 (23:30 +0200)
commit56a105f9fb80fa2f6bd01280d64744cd3e7d73c4
tree46c09e96ad6a4980bd3424fdcac0a60736914e04
parent6e2e9bb654b333eda7610270138017bbaf0b0eec
package/python-urllib3: security bump to version 1.26.6

Fix CVE-2021-33503: An issue was discovered in urllib3 before 1.26.5.
When provided with a URL containing many @ characters in the authority
component, the authority regular expression exhibits catastrophic
backtracking, causing a denial of service if a URL were passed as a
parameter or redirected to via an HTTP redirect.

https://github.com/urllib3/urllib3/blob/1.26.6/CHANGES.rst

Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com>
Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>
package/python-urllib3/python-urllib3.hash
package/python-urllib3/python-urllib3.mk