securitycriticalh11 malformed-body fix for CVE-2025-43859
h11 malformed-body handling associated with CVE-2025-43859 is addressed in this release.
securityhighstarlette version 0.49.1
starlette is pinned to version 0.49.1 to fix CVE-2025-62727 in this release.
securityhighlightgbm version 4.6.0
lightgbm is updated to version 4.6.0 for CVE-2024-43598 in this release.
securityhighCVE-2025-66418 decompression-chain fix
The unbounded number of links in the decompression chain associated with CVE-2025-66418 is addressed in this release.
securityhighexpr-lang/expr version v1.17.7
expr-lang/expr is updated to v1.17.7 to fix CVE-2025-68156 in this release.
securityhighcryptography fix for CVE-2026-26007
The cryptography issue associated with CVE-2026-26007 is addressed in this release.
securityhighpython-multipart fix for CVE-2026-24486
The arbitrary file write issue in python-multipart associated with CVE-2026-24486 is addressed in this release.
securitymediumFixes for CVE-2025-22872, CVE-2025-47914, and CVE-2025-58181
This release addresses CVE-2025-22872, CVE-2025-47914, and CVE-2025-58181.
securityhttps.go path traversal prevention
The path traversal issue in https.go is prevented in this release.
securitySeveral CVE fixes
This release addresses several CVEs.
securityAIOHTTP HTTP Parser auto_decompress fix
The AIOHTTP HTTP Parser auto_decompress feature issue involving zip bombs is addressed in this release.
securityextractTarFiles path traversal fix
The path traversal vulnerability in extractTarFiles is addressed in this release.
breakingminio replacement with seaweedfs
minio is replaced with seaweedfs in this release.