vrkommaraju opened a new issue, #45087:
URL: https://github.com/apache/superset/issues/45087

   ### Bug description
   
   name: Security Vulnerabilities Blocked by Dependency Constraints
   about: Trivy-reported vulnerabilities cannot be remediated because Superset 
dependency constraints prevent upgrading to fixed versions
   labels: security, dependencies
   
   ## Checklist
   
   - [x] I have searched existing issues and discussions.
   - [x] I am using a supported Superset version.
   - [x] I am reporting a security/dependency issue.
   - [x] I have verified the issue with the latest available package versions 
supported by Superset.
   
   ## Superset Version
   Apache Superset 6.1.0
   
   ## Environment
   
   - Deployment Type: Docker
   - Security Scanner: Trivy
   - Python Package Manager: pip
   - Operating System: Linux
   
   ## Issue Summary
   
   We are performing container security scans using Trivy against an Apache 
Superset 6.1.0 deployment.
   
   The scan reports several HIGH and MEDIUM severity vulnerabilities in 
dependencies used by Superset. 
   However, the recommended fixed versions are outside the dependency ranges 
currently supported by Superset.
   
   As a result, we are unable to remediate these findings by upgrading the 
affected libraries without breaking Superset dependency validation.
   
   We would like guidance from the maintainers on:
   
   1. Whether these vulnerabilities are applicable/exploitable in the context 
of Superset.
   2. Whether there are recommended mitigations or workarounds.
   3. Whether support for newer versions of these dependencies is planned.
   4. Whether these findings can be considered false positives or low risk for 
typical Superset deployments.
   
   ---
   
   ## Affected Dependencies
   
   | Package | Installed Version | Fixed Version Reported by Trivy | Superset 
Supported Range |
   |----------|----------|----------|----------|
   | cryptography | 46.0.7 | 48.0.1 / 49.0.0 / 50.0.0 | >=42.0.4, <47.0.0 |
   | msgpack | 1.0.8 | 1.2.1 | >=1.0.0, <1.1 |
   | pyarrow | 16.1.0 | 23.0.1 | >=16.1.0, <20 |
   
   ---
   
   ## Vulnerabilities Reported
   
   ### cryptography
   
   | Vulnerability | Severity | Installed | Fixed Version |
   |---------------|----------|------------|---------------|
   | CVE-2026-69247 | HIGH | 46.0.7 | 50.0.0 |
   | CVE-2026-69249 | HIGH | 46.0.7 | 49.0.0 |
   | GHSA-537c-gmf6-5ccf | HIGH | 46.0.7 | 48.0.1 |
   | CVE-2026-69248 | MEDIUM | 46.0.7 | 49.0.0 |
   
   ### msgpack
   
   | Vulnerability | Severity | Installed | Fixed Version |
   |---------------|----------|------------|---------------|
   | GHSA-6v7p-g79w-8964 | HIGH | 1.0.8 | 1.2.1 |
   
   ### pyarrow
   
   | Vulnerability | Severity | Installed | Fixed Version |
   |---------------|----------|------------|---------------|
   | CVE-2026-25087 | HIGH | 16.1.0 | 23.0.1 |
   
   ---
   
   ## Dependency Conflict
   
   Attempting to install the scanner-recommended version causes dependency 
conflicts.
   
   ERROR: pip's dependency resolver does not currently take into account all 
the packages that are installed.
   apache-superset 6.1.0 requires cryptography<47.0.0,>=42.0.4,
   but you have cryptography 50.0.2 which is incompatible.
   
   What We Have Verified
   
   The affected packages are already running at the highest versions currently 
compatible with Apache Superset dependency constraints:
   
   cryptography 46.0.7
   msgpack 1.0.8
   pyarrow 16.1.0
   
   
   Attempts to upgrade to the versions recommended by Trivy result in 
dependency resolution failures or unsupported package combinations.
   
   Steps to Reproduce
   Deploy Apache Superset 6.1.0.
   Run a Trivy scan against the image.
   Observe vulnerabilities reported for:
   cryptography
   msgpack
   pyarrow
   Attempt to upgrade to the reported fixed versions.
   Observe dependency constraint conflicts.
   
   Expected Behavior
   
   Either:
   
   Superset supports dependency versions containing vulnerability fixes,
   or
   Security guidance/workarounds are available that allow operators to address 
or mitigate the reported vulnerabilities.
   
   Actual Behavior
   
   Security scans identify HIGH severity findings, but the versions containing 
the fixes are currently incompatible with Apache Superset dependency 
constraints.
   
   Questions for Maintainers
   
   Are these vulnerabilities already known and assessed by the Superset project?
   Are the vulnerable code paths used by Superset?
   Is there a recommended mitigation or workaround?
   Are these findings considered exploitable in standard Superset deployments?
   
   Is support for newer versions of:
   
   cryptography
   msgpack
   pyarrow
   
   planned for an upcoming release?
   
   Since the vendor-recommended fixed versions are outside the currently 
supported dependency ranges of Superset, we are looking for project guidance on 
how these findings should be addressed and whether upgrades are planned.
   
   Thank you for your assistance.
   
   
   
   
   ### Screenshots/recordings
   
   _No response_
   
   ### Superset version
   
   6.1.0
   
   ### Python version
   
   3.12
   
   ### Node version
   
   Not applicable
   
   ### Browser
   
   Chrome
   
   ### Additional context
   
   _No response_
   
   ### Checklist
   
   - [x] I have searched Superset docs and Slack and didn't find a solution to 
my problem.
   - [x] I have searched the GitHub issue tracker and didn't find a similar bug 
report.
   - [x] I have checked Superset's logs for errors and if I found a relevant 
Python stacktrace, I included it here as text in the "additional context" 
section.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to