vrkommaraju opened a new issue, #45087: URL: https://github.com/apache/superset/issues/45087
### Bug description name: Security Vulnerabilities Blocked by Dependency Constraints about: Trivy-reported vulnerabilities cannot be remediated because Superset dependency constraints prevent upgrading to fixed versions labels: security, dependencies ## Checklist - [x] I have searched existing issues and discussions. - [x] I am using a supported Superset version. - [x] I am reporting a security/dependency issue. - [x] I have verified the issue with the latest available package versions supported by Superset. ## Superset Version Apache Superset 6.1.0 ## Environment - Deployment Type: Docker - Security Scanner: Trivy - Python Package Manager: pip - Operating System: Linux ## Issue Summary We are performing container security scans using Trivy against an Apache Superset 6.1.0 deployment. The scan reports several HIGH and MEDIUM severity vulnerabilities in dependencies used by Superset. However, the recommended fixed versions are outside the dependency ranges currently supported by Superset. As a result, we are unable to remediate these findings by upgrading the affected libraries without breaking Superset dependency validation. We would like guidance from the maintainers on: 1. Whether these vulnerabilities are applicable/exploitable in the context of Superset. 2. Whether there are recommended mitigations or workarounds. 3. Whether support for newer versions of these dependencies is planned. 4. Whether these findings can be considered false positives or low risk for typical Superset deployments. --- ## Affected Dependencies | Package | Installed Version | Fixed Version Reported by Trivy | Superset Supported Range | |----------|----------|----------|----------| | cryptography | 46.0.7 | 48.0.1 / 49.0.0 / 50.0.0 | >=42.0.4, <47.0.0 | | msgpack | 1.0.8 | 1.2.1 | >=1.0.0, <1.1 | | pyarrow | 16.1.0 | 23.0.1 | >=16.1.0, <20 | --- ## Vulnerabilities Reported ### cryptography | Vulnerability | Severity | Installed | Fixed Version | |---------------|----------|------------|---------------| | CVE-2026-69247 | HIGH | 46.0.7 | 50.0.0 | | CVE-2026-69249 | HIGH | 46.0.7 | 49.0.0 | | GHSA-537c-gmf6-5ccf | HIGH | 46.0.7 | 48.0.1 | | CVE-2026-69248 | MEDIUM | 46.0.7 | 49.0.0 | ### msgpack | Vulnerability | Severity | Installed | Fixed Version | |---------------|----------|------------|---------------| | GHSA-6v7p-g79w-8964 | HIGH | 1.0.8 | 1.2.1 | ### pyarrow | Vulnerability | Severity | Installed | Fixed Version | |---------------|----------|------------|---------------| | CVE-2026-25087 | HIGH | 16.1.0 | 23.0.1 | --- ## Dependency Conflict Attempting to install the scanner-recommended version causes dependency conflicts. ERROR: pip's dependency resolver does not currently take into account all the packages that are installed. apache-superset 6.1.0 requires cryptography<47.0.0,>=42.0.4, but you have cryptography 50.0.2 which is incompatible. What We Have Verified The affected packages are already running at the highest versions currently compatible with Apache Superset dependency constraints: cryptography 46.0.7 msgpack 1.0.8 pyarrow 16.1.0 Attempts to upgrade to the versions recommended by Trivy result in dependency resolution failures or unsupported package combinations. Steps to Reproduce Deploy Apache Superset 6.1.0. Run a Trivy scan against the image. Observe vulnerabilities reported for: cryptography msgpack pyarrow Attempt to upgrade to the reported fixed versions. Observe dependency constraint conflicts. Expected Behavior Either: Superset supports dependency versions containing vulnerability fixes, or Security guidance/workarounds are available that allow operators to address or mitigate the reported vulnerabilities. Actual Behavior Security scans identify HIGH severity findings, but the versions containing the fixes are currently incompatible with Apache Superset dependency constraints. Questions for Maintainers Are these vulnerabilities already known and assessed by the Superset project? Are the vulnerable code paths used by Superset? Is there a recommended mitigation or workaround? Are these findings considered exploitable in standard Superset deployments? Is support for newer versions of: cryptography msgpack pyarrow planned for an upcoming release? Since the vendor-recommended fixed versions are outside the currently supported dependency ranges of Superset, we are looking for project guidance on how these findings should be addressed and whether upgrades are planned. Thank you for your assistance. ### Screenshots/recordings _No response_ ### Superset version 6.1.0 ### Python version 3.12 ### Node version Not applicable ### Browser Chrome ### Additional context _No response_ ### Checklist - [x] I have searched Superset docs and Slack and didn't find a solution to my problem. - [x] I have searched the GitHub issue tracker and didn't find a similar bug report. - [x] I have checked Superset's logs for errors and if I found a relevant Python stacktrace, I included it here as text in the "additional context" section. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
