Darsh Kelaiya 7489d88734 python3-aiohttp: ignore CVE-2026-34515
Analysis:
- The upstream advisory limits the issue to aiohttp applications running
  on Windows and identifies the affected and fixed versions [1].
- The advisory-selected upstream fix rejects absolute static resource
  paths, explicitly including UNC and Windows drive paths [2].
- NVD independently describes the issue as Windows-specific and records
  the same upstream commit as the patch [3].
- Hence ignoring the CVE for now.

Reference:
[1] https://github.com/aio-libs/aiohttp/security/advisories/GHSA-p998-jp59-783m
[2] https://github.com/aio-libs/aiohttp/commit/0ae2aa076c84573df83fc1fdc39eec0f5862fe3d
[3] https://nvd.nist.gov/vuln/detail/CVE-2026-34515

Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-01 10:18:01 +05:30
2026-09-01 06:57:02 +05:30
2026-09-01 10:17:58 +05:30
2019-06-15 16:45:33 -07:00
2026-02-25 13:58:47 +05:30

Collection of layers for the OE-core universe

Main layer maintainer: Anuj Mittal anuj.mittal@oss.qualcomm.com

This repository is a collection of layers to suppliment OE-Core with additional packages, Each layer have designated maintainer Please see the respective READMEs in the layer subdirectories

S
Description
No description provided
Readme
127 MiB
Languages
BitBake 86.5%
Shell 5.8%
C 2.7%
Roff 1.9%
NASL 1.7%
Other 1.2%