Skip to content

fix(deps): upgrade bandit, decimal, mint and lazy_html for security advisories - #81

Merged
darwin67 merged 4 commits into
mainfrom
chore/dependency-advisories
Oct 11, 2026
Merged

darwin67 merged 4 commits into
mainfrom
chore/dependency-advisories

Conversation

@darwin67

Copy link
Copy Markdown
Member

mix deps.get flags four locked dependencies with published advisories. This PR upgrades each one in its own commit, and only mix.lock changes.

Package From → to Advisory Severity Where it runs
bandit 1.12.4 → 1.12.5 EEF-CVE-2026-74836: HTTP/2 connection-window starvation pins Plug processes HIGH HTTP server
EEF-CVE-2026-75484: HTTP/2 header values with CR/LF/NUL go unvalidated MEDIUM
decimal 3.1.1 → 3.1.2 EEF-CVE-2026-97853: unbounded allocation in Decimal.round/3 MEDIUM via Ecto, Postgrex, open_api_spex
mint 1.9.3 → 1.10.2 EEF-CVE-2026-82729: quadratic chunk-size parsing MEDIUM HTTP client under Req/Finch (S3)
lazy_html 0.1.12 → 0.1.13 EEF-CVE-2026-92106: unescaped SVG/MathML text (mutation XSS) LOW tests only

Bandit also brings hpax, its HPACK implementation, from 1.0.4 to 1.1.0.

Why not the latest versions

  • decimal 3.1.2, not 3.2.0. 3.2.0 came out a day ago and changes arithmetic results: it adds :subnormal and :clamped signals and fixes div/2 rounding. 3.1.2 is the patch release that carries the fix.
  • mint 1.10.2, not 1.11.0. 1.10.2 is the maintainers' backport of every 1.11.0 security fix. It also covers advisories Hex doesn't report yet: CVE-2026-82728, -82672, -91043, -92103 and -94194. It leaves out 1.11's broader HTTP/1 and HTTP/2 strictness changes.

Both upgrades are pinned only through the lock file, and mix.exs constraints are unchanged.

Verification

  • mix deps.get reports no vulnerable packages.
  • mix precommit passes: 582 tests, 0 failures.
  • Smoke test against the dev server (Bandit 1.12.5) with S3 storage on SeaweedFS:
    • A 300 KB binary upload over HTTP/1.1 and over HTTP/2 (h2c, prior knowledge) is stored in S3, read back byte-identical (sha256 match) and deleted.
    • A JSON create over HTTP/2 returns 201.

🤖 Generated with Claude Code

https://claude.ai/code/session_019fnjMN7WpEjQJD2zveakV6


Generated by Claude Code

Bandit 1.12.4 is affected by two HTTP/2 advisories, both fixed in
1.12.5:

- EEF-CVE-2026-74836 (HIGH): connection-window starvation can pin Plug
  processes indefinitely.
- EEF-CVE-2026-75484 (MEDIUM): header field values containing CR, LF
  or NUL reach the application unvalidated.

hpax, Bandit's HPACK implementation, moves from 1.0.4 to 1.1.0 with it.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019fnjMN7WpEjQJD2zveakV6
EEF-CVE-2026-97853 (MEDIUM): the places argument to Decimal.round/3
drives an unbounded allocation. Textbin does not call it, but decimal
arrives through Ecto, Postgrex and open_api_spex.

This takes the 3.1.2 patch release rather than 3.2.0. 3.2.0 shipped a
day ago and changes arithmetic results: it adds signals and fixes
div/2 rounding. That is a separate upgrade from a security fix.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019fnjMN7WpEjQJD2zveakV6
Mint is the HTTP client under Req and Finch, which talk to S3 storage
and other upstream services. 1.9.3 is affected by
EEF-CVE-2026-82729 (MEDIUM): a long run of hex digits in a chunk-size
line costs quadratic CPU to parse. 1.10.2 fixes that.

It also fixes the other Mint advisories published since 1.9.3:
unbounded HTTP/1 status and chunk-extension lines, unvalidated chunk
extensions, unbounded decoded HTTP/2 header lists and frame buffering,
and HTTP/1 transfer-coding framing. Together they are CVE-2026-82728,
-82672, -91043, -92103 and -94194.

1.10.2 is the maintainers' backport of the 1.11.0 security fixes. It
leaves out 1.11's broader HTTP/1 and HTTP/2 strictness changes.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019fnjMN7WpEjQJD2zveakV6
EEF-CVE-2026-92106 (LOW): lazy_html serializes the style and script
text of SVG and MathML elements without escaping, which allows
mutation XSS. lazy_html is a test-only dependency here, used to query
rendered LiveView HTML, so the server never serves its output. This
upgrade clears the audit warning.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019fnjMN7WpEjQJD2zveakV6
@github-actions github-actions Bot added the fix label Oct 11, 2026
@darwin67
darwin67 marked this pull request as ready for review October 11, 2026 18:38
@darwin67
darwin67 merged commit c7f6048 into main Oct 11, 2026
17 checks passed
@darwin67
darwin67 deleted the chore/dependency-advisories branch October 11, 2026 18:38
@chaba2-bot chaba2-bot Bot mentioned this pull request Oct 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants