Status
Impact
There is an open PR upstream regarding the required dependency bump to remediate this CVE seen here: https://github.com/kubeflow/pipelines/pull/11837 However, it is currently failing CI checks and so upstream maintainers will need to implement compatibility.