Update onnx, requests, pyOpenSSL, pip, pyjwt, nltk, jwcrypto, pillow, cryptography, pypdf, aiohttp and langchain to fix CVEs (MINDBREEZE42226)
ID: MINDBREEZE42226
Affected Components: Mindbreeze InSpire, Mindbreeze InSpire SaaS
Severity: 8.6 High
Status: Final
First published: August 5, 2026
CVEs: CVE-2026-22815, CVE-2026-25645, CVE-2026-27448, CVE-2026-27459, CVE-2026-27489, CVE-2026-28500, CVE-2026-30922, CVE-2026-31826, CVE-2026-3219, CVE-2026-32597, CVE-2026-33123, CVE-2026-33230, CVE-2026-33231, CVE-2026-33699, CVE-2026-34070, CVE-2026-34073, CVE-2026-34445, CVE-2026-34446, CVE-2026-34447, CVE-2026-34513, CVE-2026-34514, CVE-2026-34515, CVE-2026-34516, CVE-2026-34517, CVE-2026-34518, CVE-2026-34519, CVE-2026-34520, CVE-2026-34525, CVE-2026-39373, CVE-2026-39892, CVE-2026-40087, CVE-2026-40192, CVE-2026-40260, CVE-2026-40347, CVE-2026-40491, CVE-2026-4539, GHSA-q56x-g2fj-4rj6, GHSA-rf74-v2fm-23pw
Summary
* aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage
* Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility function
* pyOpenSSL allows TLS connection bypass via unhandled callback exception in set_tlsext_servername_callback
* pyOpenSSL DTLS cookie callback buffer overflow
* onnx Vulnerable to Path Traversal via Symlink
* ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack
* Denial of Service in pyasn1 via Unbounded Recursion
* pypdf: manipulated stream length values can exhaust RAM
* pip has an interpretation conflict due to handling both concatenated tar and ZIP files as ZIP files
* PyJWT accepts unknown `crit` header extensions
* pypdf has inefficient decoding of array-based streams
* Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in nltk
* Unauthenticated remote shutdown in nltk.app.wordnet_app
* pypdf: Possible infinite loop during recovery attempts in DictionaryObject.read_from_stream
* Path Traversal in langchain
* cryptography has incomplete DNS name constraint enforcement on peer names
* ONNX: Malicious ONNX models can crash servers by exploiting unprotected object settings.
* ONNX: Arbitrary File Read via ExternalData Hardlink Bypass in ONNX load
* ONNX: External Data Symlink Traversal
* AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector
* AIOHTTP has CRLF injection through multipart part content type header construction
* AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows
* AIOHTTP has a Multipart Header Size Bypass
* AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS
* AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect
* AIOHTTP has HTTP response splitting via \r in reason phrase
* AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass
* AIOHTTP accepts duplicate Host headers
* JWCrypto: JWE ZIP decompression bomb
* Cryptography vulnerable to buffer overflow if non-contiguous buffers were passed to APIs
* LangChain has incomplete f-string validation in prompt templates
* FITS GZIP decompression bomb in Pillow
* pypdf: Manipulated XMP metadata entity declarations can exhaust RAM
* python-multipart affected by Denial of Service via large multipart preamble or epilogue data
* gdown Affected by Arbitrary File Write via Path Traversal in gdown.extractall
* Pygments has Regular Expression Denial of Service (ReDoS) due to Inefficient Regex for GUID Matching
* ONNX: TOCTOU arbitrary file read/write in save_external_dat
* Natural Language Toolkit (NLTK) has unbounded recursion in JSONTaggedDecoder.decode_obj() may cause DoS
Hotfix Information
Fixed with following versions of Mindbreeze InSpire On-Premises or Mindbreeze InSpire SaaS:
- Mindbreeze InSpire 26.3 Release
- Mindbreeze InSpire SaaS 26.3 Release