Skip to content

chore(deps): update dependency orjson to v3.11.6 [security] - #1063

Closed
renovate-bot wants to merge 1 commit into
taskcluster:mainfrom
renovate-bot:renovate/pypi-orjson-vulnerability
Closed

renovate-bot wants to merge 1 commit into
taskcluster:mainfrom
renovate-bot:renovate/pypi-orjson-vulnerability

Conversation

@renovate-bot

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
orjson (changelog) 3.11.5 → 3.11.6 age confidence

orjson does not limit recursion for deeply nested JSON documents

CVE-2025-67221 / GHSA-hx9q-6w63-j58v

More information

Details

The orjson.dumps function in orjson before 3.11.6 does not limit recursion for deeply nested JSON documents.

Severity

  • CVSS Score: 7.7 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

ijl/orjson (orjson)

v3.11.6

Compare Source

Changed
  • orjson now includes code licensed under the Mozilla Public License 2.0 (MPL-2.0).
  • Drop support for Python 3.9.
  • ABI compatibility with CPython 3.15 alpha 5.
  • Build now depends on Rust 1.89 or later instead of 1.85.
Fixed
  • Fix sporadic crash serializing deeply nested list of dict.

Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate-bot
renovate-bot requested a review from a team as a code owner October 2, 2026 00:48
@renovate-bot
renovate-bot requested a review from jcristau October 2, 2026 00:48
@ahal

ahal commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

The diff is empty

@ahal ahal closed this Oct 5, 2026
@forking-renovate

Copy link
Copy Markdown

Renovate Ignore Notification

Because you closed this PR without merging, Renovate will ignore this update (>=3). You will get a PR once a newer version is released. To ignore this dependency forever, add it to the ignoreDeps array of your Renovate config.

If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.

@renovate-bot
renovate-bot deleted the renovate/pypi-orjson-vulnerability branch October 5, 2026 18:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants