Skip to content

fix(deps): bump starlette 1.0.0 -> 1.1.0 for PYSEC-2026-161 (BadHost)#441

Merged
corinagum merged 1 commit into
mainfrom
cg/audit-deps
May 27, 2026
Merged

fix(deps): bump starlette 1.0.0 -> 1.1.0 for PYSEC-2026-161 (BadHost)#441
corinagum merged 1 commit into
mainfrom
cg/audit-deps

Conversation

@corinagum

Copy link
Copy Markdown
Contributor

Summary

uvx pip-audit flagged a critical CVE in starlette 1.0.0 (transitive via fastapi). This PR bumps it to 1.1.0 via uv lock --upgrade-package starlette (uv picked 1.1.0, well above the 1.0.1 fix).

  • PYSEC-2026-161 / CVE-2026-48710 / GHSA-86qp-5c8j-p5mrBadHost
    • Disclosed 2026-05-22 by X41 D-Sec
    • Severity: 9.8 critical
    • Starlette reconstructs the request URL from the Host header without validation. Attackers can inject path segments via the host part, causing request.url.path to diverge from the actual routed path. Auth checks that rely on request.url.path can be bypassed while routing still hits the protected route.
    • Fix: starlette 1.0.1+; we landed on 1.1.0

Lock-only change. fastapi 0.135.2's starlette constraint already allowed the bump, so no pyproject.toml edits.

Vulnerabilities not addressed in this PR

pip-audit and Dependabot alert #5 also flag jsonpickle 1.4.2 (CVE-2020-22083, GHSA-j66q-qmrc-89rx).

  • Transitive via botbuilder-core 4.17.0, which pins jsonpickle<1.5,>=1.2. We cannot bump jsonpickle without overriding an upstream constraint on an archived library.
  • The advisory itself is disputed: "This CVE is disputed by the project author as intended functionality." It describes the documented pickle-deserialization-is-dangerous property, not a code defect. First patched version: none.
  • Recommendation: treat as accepted risk for now; track separately whether to override the constraint or remove the botbuilder integration.

Test plan

  • uvx pip-audit -r <exported requirements> --disable-pip --no-deps — starlette no longer in findings; only jsonpickle remains
  • poe check (ruff format + lint) — clean
  • poe test — 609 passed
  • pyright — 0 errors, 0 warnings

uv lock --upgrade-package starlette picked 1.1.0 (>= the 1.0.1 fix).
PYSEC-2026-161 / CVE-2026-48710 / GHSA-86qp-5c8j-p5mr — Host header
injection lets attackers poison request.url.path and bypass path-based
auth checks. Disclosed 2026-05-22.

Lock-only change; fastapi 0.135.2 already allowed the bump.

Co-Authored-By: Claude Opus 4.7 (1M context) <[email protected]>
Copilot AI review requested due to automatic review settings May 27, 2026 22:01

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot wasn't able to review any files in this pull request.

@corinagum
corinagum merged commit 7c4c038 into main May 27, 2026
4 checks passed
@corinagum
corinagum deleted the cg/audit-deps branch May 27, 2026 22:05
corinagum added a commit that referenced this pull request May 27, 2026
## Summary

Brings `origin/main` into `release` for the **2.0.12** release. **No
carve-outs this time** — Quoted Replies (PR #321) is included.

`version.json`: `2.0.11` → `2.0.12`.

Aligns with teams.ts/teams.net cadence.

## What's in this release (delta from 2.0.11)

**Features**
- Quoted Replies & new quotes features (#321) — previously held back
- SuggestedActionSubmitActivity for `suggestedAction/submit` invoke
(#434)
- Default targeted replies for targeted inbound messages (#439)
- Reactions API marked GA (#427) — already shipped in 2.0.11 actually,
ignore if duplicate
- Prompt Preview support (#397)
- Sample: opt targeted-messages into slash commands (#430)
- Sample: a2a-in-teams (#401)
- Sample: proactive message update (#405)
- Allow custom HTTP client via `AppOptions` (#416)

**Security & fixes**
- Lock JsonWebToken trust-boundary contract (#432)
- Bump starlette 1.0.0 -> 1.1.0 for PYSEC-2026-161 / BadHost (#441)
- warn when bot starts without credentials (#435)
- fix(apps): support AAD v1 issuers in Entra token validation (#422)
- fix(apps): log inbound activities at info, warn on missing
Authorization (#425)
- fix(http-stream): wait for in-flight flush before sending final close
(#419)
- Mark reactions API as GA and fix sample remove flow (#427)
- Revert serviceUrl allowlist (ADO 5310460) (#415)
- Route `app.get_app_graph` + `ctx.*_graph` to sovereign endpoints via
`cloud.graph_scope` (#402)

**Deprecations / package changes**
- Remove ai, openai, mcpplugin, a2a, and devtools packages (#413)
- Restore and deprecate devtools package (#410)
- Deprecate ai, openai, mcpplugin, a2a packages (#406)
- Add agent framework example, remove chatprompt/mcp client samples
(#386)

**Dependency bumps**
- urllib3 2.6.3 → 2.7.0 (#426)
- python-multipart 0.0.26 → 0.0.27 (#424)
- microsoft-kiota-http 1.9.7 → 1.9.9 (#423)
- idna 3.11 → 3.15 (#431)
- starlette 1.0.0 → 1.1.0 (#441, security)
- /examples/tab/Web: qs, postcss, uuid, follow-redirects bumps

## Quoted Replies inclusion notes

- Teams client rendering is in-sync with the wire format as of
2026-05-06.
- APX QR rollout completed: Public 2026-04-10, GCCH/DoD/Gallatin
2026-04-14.
- Builder methods (`prepend_quote()`, `add_quote()`), `ctx.quote()`, and
the quote-aware `ctx.reply()` behavior are all present in this release.
- `examples/quoting` is included.

## Conflict resolution

The 2.0.11 release branch had the QR-removed shape for four files; took
`main`'s (QR-included) version for all of them:
- `examples/targeted-messages/src/main.py`
- `packages/api/src/microsoft_teams/api/activities/message/message.py`
- `packages/apps/src/microsoft_teams/apps/routing/activity_context.py`
- `packages/apps/tests/test_activity_context.py`

`version.json` conflict resolved to `2.0.12`.

## Test plan

- [x] `uv sync` clean
- [x] `poe check` (ruff format + lint) — clean
- [x] `poe test` — 609 passed
- [x] `pyright` — 0 errors, 0 warnings
- [ ] Pipeline build + test stages green on `release` after merge
- [ ] Publish pipeline run with **Public** → ESRP approval → PyPI
- [ ] `pip install microsoft-teams-apps==2.0.12` smoke install

---------

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: Aamir Jawaid <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <[email protected]>
Co-authored-by: Shanmathi Mayuram Krithivasan <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants