In Python

Last updated: Sep 30, 2026


Try the strategies below in this sequence. Move to the next strategy only if the previous one does not correct the problem.

Identify the dependency chain

For strategies 2 and 3, find the direct or intermediate dependency that pulls in the vulnerable package. Use uv:

uv tree --invert --package <package>

The --invert flag turns the tree around. The package that you named is at the root. The packages that depend on it branch out from there.

Strategy 1: Update the transitive dependency

The first and simplest method is to update the vulnerable dependency directly.

uv lock -P <package>

This works when the semver ranges of the direct or intermediate dependencies let you install a version with the security patch. But a direct or intermediate dependency can pin the transitive dependency to a vulnerable version, or to a range that excludes the patched release. If it does, this command does not update it.

Strategy 2: Update the direct or intermediate dependency

If strategy 1 did not update the transitive dependency, a direct or intermediate dependency probably constrains its version. Update that dependency:

uv lock -P <direct-or-intermediate-package>

This can pull in a newer version of the transitive dependency with the security fix. But the direct dependency can be at its latest version and continue to use the vulnerable transitive package. If it does, this strategy also does not correct the problem.

Strategy 3: Use dependency overrides

When the semver ranges in the dependency tree block the patched version, force a safe version with an override.

Add this to your pyproject.toml:

[tool.uv]
override-dependencies = ["<package>>=<safe-version>"]

Strategy 4: Wait for maintainers

If the override introduces breaking changes, the safest path is to wait for the upstream maintainers to fix the vulnerability. Two releases are necessary:

  1. The maintainers of the vulnerable package publish a patched version.
  2. The maintainers of the direct or intermediate dependency release a new version that adopts the patched transitive dependency.

This procedure can continue for days or longer. In the meantime, you can accept the risk through your vulnerability management workflow. Monitor the upstream project. Update when a safe version is available.

On this page