Files
meta-openembedded/meta-python/recipes-devtools/python
Darsh Kelaiya 7489d88734 python3-aiohttp: ignore CVE-2026-34515
Analysis:
- The upstream advisory limits the issue to aiohttp applications running
  on Windows and identifies the affected and fixed versions [1].
- The advisory-selected upstream fix rejects absolute static resource
  paths, explicitly including UNC and Windows drive paths [2].
- NVD independently describes the issue as Windows-specific and records
  the same upstream commit as the patch [3].
- Hence ignoring the CVE for now.

Reference:
[1] https://github.com/aio-libs/aiohttp/security/advisories/GHSA-p998-jp59-783m
[2] https://github.com/aio-libs/aiohttp/commit/0ae2aa076c84573df83fc1fdc39eec0f5862fe3d
[3] https://nvd.nist.gov/vuln/detail/CVE-2026-34515

Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-09-01 10:18:01 +05:30
..
2024-04-07 08:36:34 -07:00
2023-06-07 09:31:32 -07:00
2024-03-04 08:56:51 -08:00
2025-04-26 15:50:27 -04:00
2024-02-19 23:22:24 -08:00
2025-04-26 15:50:27 -04:00