The push to eliminate AI agent hallucinations is moving upstream to mandatory evidence contracts. In parallel, a slew of new CVEs across core Python networking libraries demands immediate dependency audits.
Building on yesterday's coverage of tools like Rashomon intercepting AI agent false positives, a new benchmark evaluating tool-using LLMs across 3,600 human-annotated tasks establishes a 22.8% baseline false success rate for failed tool calls (earlier evaluations had cited ranges as high as 44% to 76%). Implementing a mandatory evidence contract—requiring the model to return explicit status, evidence, limitations, and next actions—reduced this false success rate to 0.8% and dropped fabricated details from 28.3% down to 0.8%.
Why it matters
While local runtime interception tools catch these failures post-execution, enforcing structured evidence contracts at the model level acts as an upstream guardrail against agents reporting green status checks on failed tests.
Maintainers released urllib3 2.8.0 to patch three distinct security vulnerabilities affecting stream and proxy handling. The fixes address CVE-2026-97687 (overwriting proxy TLS contexts with target server configurations), CVE-2026-97689 (unbounded buffer memory allocation on long chunked fields), and CVE-2026-97688 (infinite loops on compressed chunked responses).
Why it matters
Because urllib3 is a transitive dependency in botocore and requests, applications must audit site-packages and upgrade to 2.8.0 to avoid worker thread hangs and proxy TLS leaks.
A severe vulnerability tracked as CVE-2026-96760 affects Authlib versions up to 1.7.2 in its deserialize_json() function. The routine accepts JSON Web Signature (JWS) payloads with empty signature fields, allowing attackers to forge unauthenticated token data. CERT/CC issued a warning as official maintainer patches remain unconfirmed.
Why it matters
Applications verifying incoming JWS tokens via Authlib are vulnerable to identity forgery without valid cryptographic keys until patches are applied or custom verification gates are added.
Virtualenv prior to version 21.7.13 contained a high-severity vulnerability (CVE-2026-102925, CVSS 7.8) where generated bash, zsh, and fish activation scripts placed previously escaped shlex.quote values inside double quotes. Crafting directory or Tcl/Tk paths allowed shell metacharacters to break string boundaries and execute arbitrary commands when a user sourced activate.
Why it matters
Sourcing activation scripts in repositories with unvetted directory names can trigger local code execution under the developer's shell privileges.
Security advisory CVE-2026-102877 was issued for Fider versions <= 0.37.0, detailing a Server-Side Request Forgery (SSRF) flaw in its webhook and OAuth delivery components. Attackers were able to bypass initial URL domain checks if DNS records modified IP resolutions between registration and delivery execution. Version 0.38.0 resolves the issue.
Why it matters
Validating webhook target IP addresses solely at registration time leaves internal network ranges exposed to DNS rebinding attacks during delivery.
Adding to the ongoing thread of payment webhook resilience and raw byte HMAC verification we've tracked this month, a newly detailed ingress architecture solves timestamp expirations during dead-letter queue (DLQ) replays. Replaying failed webhooks after Stripe's 300-second tolerance window normally causes cryptographic verification to fail; the new approach verifies original HMAC signatures at initial receipt, stores raw payloads in local SQLite WAL storage, and uses an internal proxy to re-sign replayed events with fresh timestamps before pushing downstream.
Why it matters
Using a re-signing ingress proxy allows payment systems to replay aged DLQ webhooks safely without widening SDK timestamp tolerance windows or disabling signature checks.
Evidence Contracts Replace Baseline Model Assertions in Agent Harnesses Tool-using LLM agents frequently declare task success despite crashed runners or unexecuted checks, prompting developers to enforce structured evidence schemas containing explicit logs and artifacts before code merges.
Transitive Dependency Flaws Compromise Transport Layers Simultaneous disclosures across urllib3, CPython, and virtualenv demonstrate how subtle state-machine and path-handling bugs in core libraries expose downstream production runtimes to memory exhaustion and arbitrary code execution.
Send-Time Validation Standardizes Webhook Security Controls Modern webhook architectures are moving from creation-time checks to strict send-time IP pinning and raw-byte signature verification to prevent SSRF and replay vulnerabilities.
What to Expect
2026-11-12—PostgreSQL 14 reaches End-of-Life (EOL); official security patches and bug fixes will cease.
How We Built This Briefing
Every story, researched.
Every story verified across multiple sources before publication.
🔍
Scanned
Across multiple search engines and news databases
514
📖
Read in full
Every article opened, read, and evaluated
128
⭐
Published today
Ranked by importance and verified across sources
6
— The Staff Safety Desk
🎙 Listen as a podcast
Subscribe in your favorite podcast app to get each new briefing delivered automatically as audio.
Apple Podcasts
Library tab → ••• menu → Follow a Show by URL → paste