Skip to content

sec: diskcache <=5.6.3 has unpatched CVE — monitor for upstream fix #3446

@mrveiss

Description

@mrveiss

Summary

diskcache in requirements.txt (root) has an open CVE with no patched version available upstream (Dependabot alert #278, dismissed 2026-04-04 as tolerable_risk).

Context

diskcache is pulled in as a transitive dependency. The vulnerable version range covers all published releases as of 2026-04-04.

Action

  • Monitor the diskcache PyPI release page for a patched release
  • When a fix is published: add an explicit diskcache>=<patched_version> pin to the relevant requirements file and close this issue
  • If no fix within 90 days, audit whether diskcache is still actively used and consider replacing it

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions