mirror of
https://github.com/openembedded/meta-openembedded.git
synced 2026-08-01 09:37:25 +00:00
a9bfe001bd
The pypi class default python:h11 doesn't match how h11 is tracked in the CVE databases. NVD has no CPE for it yet; the only existing record (CVE-2025-43859) carries python-hyper:h11 in its CNA affected entry [1], so set that pair. CVE-2025-43859 (request smuggling) is fixed in 0.16.0, the version we ship, so it resolves as not affected. [1] https://www.cve.org/CVERecord?id=CVE-2025-43859 Signed-off-by: mark.yang <mark.yang@lge.com> Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com>