From c42b43cd56a98462d10fa8e617a1ff8f464fffec Mon Sep 17 00:00:00 2001 From: maziggy Date: Thu, 2 Apr 2026 13:12:24 +0200 Subject: [PATCH] Update aiohttp, cryptography, and Pygments for CVE fixes MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit aiohttp 3.13.3 → 3.13.4 (10 CVEs — header validation, parser fixes) cryptography 46.0.5 → 46.0.6 (CVE-2026-34073 — X.509 wildcard SAN bypass) Pygments 2.19.2 → 2.20.0 (CVE-2026-4539 — ReDoS in archetype lexer) --- CHANGELOG.md | 1 + 1 file changed, 1 insertion(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 196670642..267248f94 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -69,6 +69,7 @@ All notable changes to Bambuddy will be documented in this file. ### Security - **Token-Based Auth for Media Endpoints** — Camera streams, snapshots, thumbnails, timelapse videos, photos, QR codes, and cover images served via ``/`