RHOAIENG-64887: CVE-2026-48710 rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9: Starlette: Security restriction bypass via malformed HTTP Host header [rhoai-2.25]#3747
Conversation
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
Hi @jira-autofix[bot]. Thanks for your PR. I'm waiting for a opendatahub-io member to verify that this patch is reasonable to test. If it is, they should reply with Regular contributors should join the org to skip this step. Once the patch is verified, the new status will be reflected by the I understand the commands that are listed here. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
|
Note Reviews pausedIt looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the Use the following commands to manage reviews:
Use the checkboxes below for quick actions:
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository YAML (base), Central YAML (inherited), Repository UI (inherited) Review profile: CHILL Plan: Enterprise Run ID: 📒 Files selected for processing (1)
🚧 Files skipped from review as they are similar to previous changes (1)
📝 WalkthroughWalkthroughThis PR updates Estimated code review effort🎯 1 (Trivial) | ⏱️ ~2 minutes 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #3747 +/- ##
=======================================
Coverage 27.46% 27.46%
=======================================
Files 38 38
Lines 4064 4064
Branches 670 670
=======================================
Hits 1116 1116
Misses 2859 2859
Partials 89 89
Flags with carried forward coverage won't be shown. Click here to find out more. Continue to review full report in Codecov by Sentry.
🚀 New features to boost your workflow:
|
fa88d83 to
1c919dd
Compare
…via malformed HTTP Host header Add starlette>=1.0.1 floor constraint to cve-constraints.txt. All images already resolve starlette 1.1.0 which satisfies the fix; this constraint prevents future downgrades below the patched version.
bf6af4d to
59b8a59
Compare
|
Closing — per-image RHOAIENG CVE trackers are now triaged as not_fixable via AGENTS.md instructions (PR #3780). The centralized fix for CVE-2026-48710 is already in |
Add starlette>=1.0.1 floor constraint to cve-constraints.txt.
All images already resolve starlette 1.1.0 which satisfies the fix;
this constraint prevents future downgrades below the patched version.
Summary by CodeRabbit
Release Notes