diff --git a/requirements.txt b/requirements.txt index 550ea9fdb..614d37fb8 100644 --- a/requirements.txt +++ b/requirements.txt @@ -101,6 +101,14 @@ urllib3>=2.7.0 # directly to stop the resolver from picking the vulnerable build. starlette>=1.0.1 +# Transitive of pywebpush (unpinned `aiohttp` requirement). aiohttp 3.13.5 +# has CVE-2026-34993 and CVE-2026-47265, both fixed in 3.14.0. pywebpush +# doesn't declare an upper bound either way, so without this pin the +# resolver keeps installing the vulnerable 3.13.x line. Our direct usage +# in services/external_camera.py (ClientSession, ClientTimeout, ClientError, +# iter_chunked) is unaffected by 3.14.0. +aiohttp>=3.14.0 + # Plate Detection (optional - enables build plate empty detection) opencv-python-headless>=4.8.0 numpy>=1.24.0