Change8

v3.10.25

📦 quay-ioView on GitHub →
🐛 5 fixes🔧 5 symbols

Summary

This release addresses several CVEs by upgrading dependencies like pyasn1 and pillow, and patching vulnerabilities in decode-uri-component, brace-expansion, and js-yaml. It also includes a fix to prevent SSRF in repository sources.

🐛 Bug Fixes

  • CVE-2026-45822: Fixed a vulnerability in decode-uri-component.
  • CVE-2026-59885: Upgraded pyasn1 to 0.6.4 to address a vulnerability.
  • CVE-2026-13149: Addressed a vulnerability in brace-expansion.
  • CVE-2026-59869: Addressed a vulnerability in js-yaml.
  • PROJQUAY-12356: Prevented SSRF in repository sources.

Affected Symbols