Skip to content

fix: bump pymongo for CVE-2026-88029 - #6538

Open
Artemon-line wants to merge 2 commits into
ogx-ai:mainfrom
Artemon-line:fix-CVE-2026-88029
Open

Artemon-line wants to merge 2 commits into
ogx-ai:mainfrom
Artemon-line:fix-CVE-2026-88029

Conversation

@Artemon-line

Copy link
Copy Markdown
Contributor

Bump pymongo>=4.18.1 to fix CVE-2026-88029.

Update pymongo>=4.18.1 dependency to fix CVE-2026-88029.

Signed-off-by: Artemy <ahladenk@redhat.com>
@Artemon-line

Copy link
Copy Markdown
Contributor Author

@cdoern @leseb @skamenan7
Please take a look, thanks.

Move the kvstore dependencies from core storage into the provider registry as a KVSTORE_DEPS constant so the Dependabot constraint-sync workflow can keep the version floor in sync. Apply the pymongo>=4.18.1 floor to fix CVE-2026-88029 in the runtime pip_packages surfaced by the builtin responses provider.

Signed-off-by: Matthew Farrellee <matt@cs.wisc.edu>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants