Darsh Kelaiya
d070b08b56
python3-aiohttp: fix CVE-2026-54280
...
This patch applies the upstream fix as referenced in [2], using
the commit shown in [1].
[1] https://github.com/aio-libs/aiohttp/commit/a762eda5242f6490d6ba667533193f8b473ad587
[2] https://github.com/advisories/GHSA-9x8q-7h8h-wcw9
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-08-24 12:58:50 +05:30
Darsh Kelaiya
bf97296869
python3-aiohttp: fix CVE-2026-54279
...
This patch applies the upstream fix as referenced in [2], using
the commit shown in [1].
[1] https://github.com/aio-libs/aiohttp/commit/a329a7aacad5284f087af36103aff778746da0f2
[2] https://github.com/advisories/GHSA-2fqr-mr3j-6wp8
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-08-24 12:58:50 +05:30
Darsh Kelaiya
813105c96d
python3-aiohttp: fix CVE-2026-54278
...
This patch applies the upstream fix as referenced in [2], using
the commit shown in [1].
[1] https://github.com/aio-libs/aiohttp/commit/4f7480e474cccc6a8cc2c92ad3f17a31dedf8232
[2] https://github.com/advisories/GHSA-g3cq-j2xw-wf74
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-08-24 12:58:49 +05:30
Darsh Kelaiya
45e39122a3
python3-aiohttp: fix CVE-2026-54277
...
This patch applies the upstream fix as referenced in [2], using
the commit shown in [1].
[1] https://github.com/aio-libs/aiohttp/commit/5ab61bb4cd88f19b712f12c7c9295fe262bf804d
[2] https://github.com/advisories/GHSA-63hw-fmq6-xxg2
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-08-24 12:58:49 +05:30
Darsh Kelaiya
4061d30051
python3-aiohttp: fix CVE-2026-54276
...
This patch applies the upstream fix as referenced in [2], using
the commit shown in [1].
[1] https://github.com/aio-libs/aiohttp/commit/38d16060037e1bfcd6d677abababa3c2a4bb58fa
[2] https://github.com/advisories/GHSA-hpj7-wq8m-9hgp
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-08-24 12:58:48 +05:30
Darsh Kelaiya
22f7bc5b39
python3-aiohttp: fix CVE-2026-54275
...
This patch applies the upstream fix as referenced in [2], using
the commit shown in [1].
[1] https://github.com/aio-libs/aiohttp/commit/0ca2b6c28a25726527a8b60f25960262a91ed0e0
[2] https://github.com/advisories/GHSA-4m7w-qmgq-4wj5
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-08-24 12:58:48 +05:30
Darsh Kelaiya
81b7b1e1c7
python3-aiohttp: fix CVE-2026-54274
...
This patch applies the upstream fix as referenced in [2], using
the commit shown in [1].
[1] https://github.com/aio-libs/aiohttp/commit/14b6ee851fb16ec199acb950de0c82d476799e7d
[2] https://github.com/advisories/GHSA-xcgm-r5h9-7989
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-08-24 12:58:47 +05:30
Darsh Kelaiya
6de7cbdd5b
python3-aiohttp: fix CVE-2026-50269
...
This patch applies the upstream fix as referenced in [2], using
the commit shown in [1].
[1] https://github.com/aio-libs/aiohttp/commit/bf88077ebb14f4c29924b8e8904cba20c55c28b8
[2] https://github.com/advisories/GHSA-m6qw-4cw2-hm4m
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-08-24 12:58:47 +05:30
Darsh Kelaiya
1936909624
python3-aiohttp: fix CVE-2026-47265
...
This patch applies the upstream fix as referenced in [2], using
the commit shown in [1].
[1] https://github.com/aio-libs/aiohttp/commit/f54c40851b0d6c4bbdab97ba518a223adda32478
[2] https://github.com/advisories/GHSA-hg6j-4rv6-33pg
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-08-24 12:58:46 +05:30
Darsh Kelaiya
e389fd34bc
python3-aiohttp: fix CVE-2026-34993
...
This patch applies the upstream fix as referenced in [2], using
the commit shown in [1].
[1] https://github.com/aio-libs/aiohttp/commit/dcf40f30637e8752c76781cf6703b5a236749a00
[2] https://github.com/advisories/GHSA-jg22-mg44-37j8
Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com >
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com >
2026-08-24 12:58:46 +05:30
Gyorgy Sarvari
4ee0103733
python3-aiohttp: mark fixed CVEs are patched
...
All these CVEs have been fixed already, the relevant NVD
reports mention it explicitly that 3.13.4 is fixed, along
with referencing the commit that fixes the respective
vulnerabilities. However each of these are tracked without
version info by NVD -.-
Due to this, mark them explicitly as patched.
Relevant reports:
https://nvd.nist.gov/vuln/detail/CVE-2026-22815
https://nvd.nist.gov/vuln/detail/CVE-2026-34513
https://nvd.nist.gov/vuln/detail/CVE-2026-34514
https://nvd.nist.gov/vuln/detail/CVE-2026-34515
https://nvd.nist.gov/vuln/detail/CVE-2026-34516
https://nvd.nist.gov/vuln/detail/CVE-2026-34517
https://nvd.nist.gov/vuln/detail/CVE-2026-34518
https://nvd.nist.gov/vuln/detail/CVE-2026-34519
https://nvd.nist.gov/vuln/detail/CVE-2026-34520
https://nvd.nist.gov/vuln/detail/CVE-2026-34525
Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
2026-04-06 09:46:31 -07:00
Gyorgy Sarvari
844f87dd10
python3-aiohttp: upgrade 3.13.4 -> 3.13.5
...
Changelog:
Skipped the duplicate singleton header check in lax mode (the default for response
parsing). In strict mode (request parsing, or -X dev), all RFC 9110 singletons
are still enforced.
Signed-off-by: Gyorgy Sarvari <skandigraun@gmail.com >
Signed-off-by: Khem Raj <khem.raj@oss.qualcomm.com >
2026-04-06 09:46:31 -07:00