awx
Chainguard
Status
Impact
This vulnerability is part of urllib, which is vendored into pip, and there are significant changes between the current version and the fixed version. As such, we cannot update or patch it, and will require upstream to produce a fix. Additionally, this vulnerability only applies when used with Pyodide, which significantly restricts the attack surface. See the following for more information: https://github.com/advisories/GHSA-48p4-8xcf-vxj5
Status