Package
gitlab-toolbox-ce-fips-18.7
Component
urllib3
Latest update
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
This vulnerability affects urllib3 1.26.20, a transitive dependency in the GitLab toolbox component. The vulnerability is fixed in urllib3 >= 2.6.3, but upgrading is blocked by Python version constraints in the dependency chain.
Dependency Chain:
The botocore urllib3 constraint changes based on Python version:
With Python 3.9, the package is locked to urllib3 1.26.x and cannot upgrade to the fixed 2.6.3+ version without breaking the dependency resolver. Upgrading urllib3 requires either upgrading to Python 3.10+ or removing/replacing awscli.
In order to remediate this vulnerability, upstream GitLab must upgrade the CNG toolbox component to Python 3.10 or later, which will allow botocore's urllib3 constraint to permit the 2.x branch containing the security fix.
Status