Skip to content

chore(deps): refresh rpm lockfiles (master) [SECURITY]#1010

Open
red-hat-konflux[bot] wants to merge 1 commit intomasterfrom
konflux/mintmaker/master-master/lock-file-maintenance-vulnerability
Open

chore(deps): refresh rpm lockfiles (master) [SECURITY]#1010
red-hat-konflux[bot] wants to merge 1 commit intomasterfrom
konflux/mintmaker/master-master/lock-file-maintenance-vulnerability

Conversation

@red-hat-konflux
Copy link
Contributor

This PR contains the following updates:

File rpms.in.yaml:

Package Change
nodejs 1:22.19.0-2.module+el9.6.0+23473+45664c2d -> 1:22.22.0-1.module+el9.7.0+23896+b5802de9
nodejs-docs 1:22.19.0-2.module+el9.6.0+23473+45664c2d -> 1:22.22.0-1.module+el9.7.0+23896+b5802de9
nodejs-full-i18n 1:22.19.0-2.module+el9.6.0+23473+45664c2d -> 1:22.22.0-1.module+el9.7.0+23896+b5802de9
nodejs-libs 1:22.19.0-2.module+el9.6.0+23473+45664c2d -> 1:22.22.0-1.module+el9.7.0+23896+b5802de9
npm 1:10.9.3-1.22.19.0.2.module+el9.6.0+23473+45664c2d -> 1:10.9.4-1.22.22.0.1.module+el9.7.0+23896+b5802de9
libbrotli 1.0.9-7.el9_5 -> 1.0.9-9.el9_7
openssl 1:3.5.1-4.el9_7 -> 1:3.5.1-7.el9_7

Scrapy: python-scrapy: brotli: Python brotli decompression bomb DoS

CVE-2025-6176

More information

Details

Scrapy are vulnerable to a denial of service (DoS) attack due to a flaw in its brotli decompression implementation. The protection mechanism against decompression bombs fails to mitigate the brotli variant, allowing remote servers to crash clients with less than 80GB of available memory. This occurs because brotli can achieve extremely high compression ratios for zero-filled data, leading to excessive memory consumption during decompression.

Severity

Important

References

🔧 This Pull Request updates lock files to use the latest dependency versions.


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

To execute skipped test pipelines write comment /ok-to-test.


Documentation

Find out how to configure dependency updates in MintMaker documentation or see all available configuration options in Renovate documentation.

Signed-off-by: red-hat-konflux <126015336+red-hat-konflux[bot]@users.noreply.github.com>
@red-hat-konflux red-hat-konflux bot force-pushed the konflux/mintmaker/master-master/lock-file-maintenance-vulnerability branch from 32b0660 to befa314 Compare March 6, 2026 21:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants