Third-Party Package Updates in Splunk SOAR - August 2026

Advisory ID: SVD-2026-0805

CVE ID: 

Published: 2026-08-19

Last Update: 2026-08-19

Description

Splunk remedied common vulnerabilities and exposures (CVEs) in Third Party Packages in Splunk SOAR version 8.6.0, and higher.

PackageRemediationCVESeverity
@xmldom/xmldom1Upgraded @xmldom/xmldom to version 0.8.12CVE-2026-34601High
aiohttp2Upgraded aiohttp to version 3.13.4MultipleMedium
ajv3Upgraded ajv to version 8.18.0CVE-2025-69873Low
azure-core4Upgraded azure-core to version 1.38.0CVE-2026-21226High
bn.js5Upgraded bn.js to version 5.2.3CVE-2026-2739Medium
brace-expansion6Upgraded brace-expansion to version 2.1.0CVE-2026-33750Medium
cryptography7Upgraded cryptography to version 46.0.5CVE-2026-26007High
diff8Upgraded diff to version 8.0.3CVE-2026-24001High
django9Upgraded django to version 5.2.16MultipleHigh
django10Upgraded django to version 4.2.30MultipleHigh
dompurify11Upgraded dompurify to version 3.3.3MultipleMedium
flatted12Upgraded flatted to version 3.4.2MultipleHigh
gitpython13Upgraded gitpython to version 3.1.50MultipleCritical
immutable14Upgraded immutable to version 5.1.5CVE-2026-29063Critical
koa15Upgraded koa to version 3.1.2CVE-2026-27959High
langchain-core16Upgraded langchain-core to version 1.2.28CVE-2026-40087Medium
langgraph17Upgraded langgraph to version 1.0.10CVE-2026-28277Medium
lodash18Upgraded lodash to version 4.18.1MultipleHigh
lxml19Upgraded lxml to version 6.1.1CVE-2026-41066High
minimatch20Upgraded minimatch to version 5.1.9CVE-2026-26996High
picomatch21Upgraded picomatch to version 2.3.2MultipleHigh
postgresql22Upgraded postgresql to 15.17MultipleHigh
pyasn123Upgraded pyasn1 to version 0.6.3CVE-2026-30922High
pyjwt24Upgraded pyjwt to version 2.12.0CVE-2026-32597High
python-dotenv25Upgraded python-dotenv to version 1.2.2CVE-2026-28684Medium
qs26Upgraded qs to version 6.15.0CVE-2026-2391High
tornado27Upgraded tornado to version 6.5.5MultipleHigh
virtualenv28Upgraded virtualenv to version 20.36.1CVE-2026-22702Medium
werkzeug29Upgraded werkzeug to version 3.1.6MultipleMedium
yaml30Upgraded yaml to version 1.10.3CVE-2026-33532Medium
pbkdf231Upgraded pbkdf2 to version 3.1.6MultipleCritical
jspdf32Upgraded jspdf to version 4.2.1MultipleCritical
ngnix33Upgraded ngnix to version 1.30.2MultipleHigh

1 Upgraded @xmldom/xmldom to remedy CVE-2026-34601 in Splunk SOAR 8.6.0.

2 Upgraded aiohttp to remedy CVE-2026-22815, CVE-2026-34513, CVE-2026-34514, CVE-2026-34515, CVE-2026-34516, CVE-2026-34517, CVE-2026-34518, CVE-2026-34519, CVE-2026-34520, and CVE-2026-34525 in Splunk SOAR 8.6.0.

3 Upgraded ajv to remedy CVE-2025-69873 in Splunk SOAR 8.6.0.

4 Upgraded azure-core to remedy CVE-2026-21226 in Splunk SOAR 8.6.0.

5 Upgraded bn.js to remedy CVE-2026-2739 in Splunk SOAR 8.6.0.

6 Upgraded brace-expansion to remedy CVE-2026-33750 in Splunk SOAR 8.6.0.

7 Upgraded cryptography to remedy CVE-2026-26007 in Splunk SOAR 8.6.0.

8 Upgraded diff to remedy CVE-2026-24001 in Splunk SOAR 8.6.0.

9 Upgraded django to remedy CVE-2025-13473, CVE-2025-14550, CVE-2026-1207, CVE-2026-1285, CVE-2026-1287, CVE-2026-1312, CVE-2026-25673, and CVE-2026-25674 in Splunk SOAR 8.6.0 at sorcery/dependencies/workspaces/automation_3.13.

10 Upgraded django to remedy CVE-2025-13473, CVE-2025-14550, CVE-2026-1207, CVE-2026-1285, CVE-2026-1287, CVE-2026-1312, CVE-2026-25673, and CVE-2026-25674 in Splunk SOAR 8.6.0 at sorcery/dependencies/workspaces/automation_3.9

11 Upgraded dompurify to remedy CVE-2025-15599 and CVE-2026-0540 in Splunk SOAR 8.6.0.

12 Upgraded flatted to remedy CVE-2026-33228 and CVE-2026-32141 in Splunk SOAR 8.6.0.

13 Upgraded gitpython to remedy CVE-2026-42215, CVE-2026-42284, CVE-2026-44243 and CVE-2026-44244 in Splunk SOAR 8.6.0.

14 Upgraded immutable to remedy CVE-2026-29063 in Splunk SOAR 8.6.0.

15 Upgraded koa to remedy CVE-2026-27959 in Splunk SOAR 8.6.0.

16 Upgraded langchain-core to remedy CVE-2026-40087 in Splunk SOAR 8.6.0.

17 Upgraded langgraph to remedy CVE-2026-28277 in Splunk SOAR 8.6.0.

18 Upgraded lodash to remedy CVE-2026-4800, CVE-2025-13465 and CVE-2026-2950 in Splunk SOAR 8.6.0.

19 Upgraded lxml to remedy CVE-2026-41066 in Splunk SOAR 8.6.0.

20 Upgraded minimatch to remedy CVE-2026-26996 in Splunk SOAR 8.6.0.

21 Upgraded picomatch to remedy CVE-2026-33671 and CVE-2026-33672 in Splunk SOAR 8.6.0.

22 Upgraded postgresql to remedy CVE-2026-2004, CVE-2026-2005 and CVE-2026-2006 in Splunk SOAR 8.6.0.

23 Upgraded pyasn1 to remedy CVE-2026-30922 in Splunk SOAR 8.6.0.

24 Upgraded pyjwt to remedy CVE-2026-32597 in Splunk SOAR 8.6.0.

25 Upgraded python-dotenv to remedy CVE-2026-28684 in Splunk SOAR 8.6.0.

26 Upgraded qs to remedy CVE-2026-2391 in Splunk SOAR 8.6.0.

27 Upgraded tornado to remedy CVE-2025-67724, CVE-2025-67725, CVE-2025-67726, CVE-2026-31958 and CVE-2026-35536 in Splunk SOAR 8.6.0.

28 Upgraded virtualenv to remedy CVE-2026-22702 in Splunk SOAR 8.6.0.

29 Upgraded werkzeug to remedy CVE-2026-21860, CVE-2025-66221 and CVE-2026-27199 in Splunk SOAR 8.6.0.

30 Upgraded yaml to remedy CVE-2026-33532 in Splunk SOAR 8.6.0.

31 Upgraded pbkdf2 to remedy CVE-2025-6545 and CVE-2025-6547 in Splunk SOAR 8.6.0.

32 Upgraded jspdf to remedy CVE-2025-68428, CVE-2026-24040, CVE-2026-24043, CVE-2026-24133, CVE-2026-24737, CVE-2026-25535, CVE-2026-25755, CVE-2026-25940, CVE-2026-31898 and CVE-2026-31938 in Splunk SOAR 8.6.0.

33 Upgraded ngnix to remedy CVE-2026-9256, CVE-2026-42945, CVE-2026-42946, CVE-2026-42934, CVE-2026-40460, CVE-2026-40701, CVE-2026-27654, CVE-2026-27784, CVE-2026-32647, CVE-2026-27651, CVE-2026-28753, CVE-2026-28755, CVE-2026-1642 and CVE-2025-53859 in Splunk SOAR 8.6.0.

Solution

Upgrade Splunk SOAR to version 8.6.0, or higher.

Product Status

ProductBase VersionAffected VersionFix Version
Splunk SOAR8.6Below 8.6.08.6.0

Severity

For the CVEs in this list, Splunk adopted the vendor’s severity rating or the National Vulnerability Database (NVD) common vulnerability scoring system (CVSS) rating, as available.