Skip to content

fix(deps): vuln aiohttp (major → 3.14.3) [python/aiohttp/simple_app/requirements.txt] - #240

Open
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/major/pip/simple_app/2-1788172105
Open

fix(deps): vuln aiohttp (major → 3.14.3) [python/aiohttp/simple_app/requirements.txt]#240
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/major/pip/simple_app/2-1788172105

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown
Contributor

Summary: Critical-severity security update — 1 package upgraded (MAJOR changes included)

Manifests changed:

  • python/aiohttp/simple_app/requirements.txt (pip)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
aiohttp 1.2.0 3.14.3 major Direct 2 CRITICAL, 16 HIGH, 70 MEDIUM, 45 LOW

Warning

Major Version Upgrade

This update includes major version changes that may contain breaking changes. Please:

  • Review the changelog/release notes for breaking changes
  • Test thoroughly in a staging environment
  • Update any code that depends on changed APIs
  • Ensure all tests pass before merging

Security Details

🚨 Critical & High Severity (18 fixed)
Package CVE Severity Summary Unsafe Version Fixed In Case
aiohttp PYSEC-2026-2102 critical - 1.2.0 3.13.4 -
aiohttp CVE-2026-34520 critical AIOHTTP: C parser (llhttp) accepts null bytes and control characters in response header values - header injection / security bypass 1.2.0 - -
aiohttp CVE-2024-30251 HIGH Denial of service when trying to parse malformed POST requests in aiohttp 1.2.0 - -
aiohttp GHSA-5m98-qgg9-wh84 HIGH aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests 1.2.0 3.9.4 -
aiohttp CVE-2024-23334 HIGH aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal 1.2.0 - -
aiohttp GHSA-5h86-8mv2-jq9f HIGH aiohttp is vulnerable to directory traversal 1.2.0 3.9.2 -
aiohttp PYSEC-2026-1101 high AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb 1.2.0 3.13.3 -
aiohttp CVE-2023-49081 high aiohttp's ClientSession is vulnerable to CRLF injection via version 1.2.0 - -
aiohttp PYSEC-2024-24 HIGH - 1.2.0 1c335944d6a8b1298baf179b7c0b3069f10c514b -
aiohttp PYSEC-2023-250 high - 1.2.0 1e86b777e61cf4eefc7d92fa57fa19dcc676013b -
aiohttp PYSEC-2026-1098 HIGH aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests 1.2.0 3.9.4 -
aiohttp CVE-2026-34516 high AIOHTTP: Multipart Header Size Bypass 1.2.0 - -
aiohttp PYSEC-2026-2098 high - 1.2.0 3.13.4 -
aiohttp GHSA-cq5v-8q36-5273 HIGH AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response) 1.2.0 3.14.3 -
aiohttp CVE-2026-69244 high AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response) 1.2.0 - -
aiohttp PYSEC-2026-3545 high AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response) 1.2.0 3.14.3 -
aiohttp CVE-2025-69223 high AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb 1.2.0 - -
aiohttp GHSA-6mq8-rvhq-8wgg HIGH AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb 1.2.0 3.13.3 -
ℹ️ Other Vulnerabilities (115)
Package CVE Severity Summary Unsafe Version Fixed In Case
aiohttp PYSEC-2023-251 medium - 1.2.0 e4ae01c2077d2cfa116aa82e4ff6866857f7c466 -
aiohttp CVE-2023-49082 medium aiohttp's ClientSession is vulnerable to CRLF injection via method 1.2.0 - -
aiohttp PYSEC-2026-1099 medium AIOHTTP's unicode processing of header values could cause parsing discrepancies 1.2.0 3.13.3 -
aiohttp PYSEC-2026-2097 medium - 1.2.0 3.13.4 -
aiohttp CVE-2025-69227 medium AIOHTTP vulnerable to DoS when bypassing asserts 1.2.0 - -
aiohttp PYSEC-2026-1107 medium AIOHTTP vulnerable to DoS when bypassing asserts 1.2.0 3.13.3 -
aiohttp CVE-2025-69224 medium AIOHTTP's Unicode processing of header values could cause parsing discrepancies 1.2.0 - -
aiohttp PYSEC-2026-2104 medium - 1.2.0 3.14.0 -
aiohttp CVE-2026-34993 medium AIOHTTP Vulnerable to Deserialization of Untrusted Data 1.2.0 - -
aiohttp CVE-2026-54278 medium AIOHTTP: Unread Compressed Request Bodies Bypass client_max_size During Cleanup 1.2.0 - -
aiohttp CVE-2026-54276 medium AIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges 1.2.0 - -
aiohttp PYSEC-2026-2109 medium - 1.2.0 3.14.1 -
aiohttp CVE-2026-54277 medium AIOHTTP: C HTTP Parser Bypasses max_line_size for Fragmented Lines 1.2.0 - -
aiohttp PYSEC-2026-1097 medium AIOHTTP vulnerable to brute-force leak of internal static file path components 1.2.0 3.13.3 -
aiohttp CVE-2025-69226 medium AIOHTTP allows for a brute-force leak of internal static filepath components 1.2.0 - -
aiohttp PYSEC-2026-2110 medium - 1.2.0 3.14.1 -
aiohttp PYSEC-2026-2094 medium - 1.2.0 3.13.4 -
aiohttp CVE-2026-22815 medium AIOHTTP: Uncapped memory usage possible through aiohttp allowing unlimited trailer headers 1.2.0 - -
aiohttp PYSEC-2024-26 medium - 1.2.0 33ccdfb0a12690af5bb49bda2319ec0907fa7827 -
aiohttp PYSEC-2026-2111 medium - 1.2.0 3.14.1 -
aiohttp CVE-2026-34515 medium AIOHTTP: UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows 1.2.0 - -
aiohttp CVE-2024-23829 medium aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators 1.2.0 - -
aiohttp PYSEC-2026-2108 medium - 1.2.0 3.14.1 -
aiohttp CVE-2026-54274 medium AIOHTTP: Incomplete websocket frame payloads bypass memory limits 1.2.0 - -
aiohttp GHSA-8qpw-xqxj-h4r2 MODERATE aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators 1.2.0 3.9.2 -
aiohttp PYSEC-2023-246 MODERATE - 1.2.0 d5c12ba890557a575c313bb3017910d7616fce3d -
aiohttp GHSA-p998-jp59-783m MODERATE AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows 1.2.0 3.13.4 -
aiohttp GHSA-m5qp-6w8w-w647 MODERATE AIOHTTP has a Multipart Header Size Bypass 1.2.0 3.13.4 -
aiohttp CVE-2026-69243 MODERATE AIOHTTP: HTTP request smuggling via WebSocket upgrade 1.2.0 - -
aiohttp PYSEC-2026-3546 MODERATE AIOHTTP: HTTP request smuggling via WebSocket upgrade 1.2.0 3.14.2 -
aiohttp GHSA-mfx4-hv73-q22v MODERATE AIOHTTP: HTTP request smuggling via WebSocket upgrade 1.2.0 3.14.2 -
aiohttp PYSEC-2026-1102 MODERATE aiohttp Cross-site Scripting vulnerability on index pages for static file handling 1.2.0 3.9.4 -
aiohttp CVE-2024-27306 MODERATE aiohttp vulnerable to XSS on index pages for static file handling 1.2.0 - -
aiohttp GHSA-7gpw-8wmc-pm8g MODERATE aiohttp Cross-site Scripting vulnerability on index pages for static file handling 1.2.0 3.9.4 -
aiohttp PYSEC-2023-120 MODERATE aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser 1.2.0 3.8.5 -
aiohttp GHSA-jj3x-wxrx-4x23 MODERATE AIOHTTP vulnerable to DoS when bypassing asserts 1.2.0 3.13.3 -
aiohttp CVE-2023-37276 MODERATE aiohttp vulnerable to HTTP request smuggling 1.2.0 - -
aiohttp GHSA-45c4-8wx5-qw6w MODERATE aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser 1.2.0 3.8.5 -
aiohttp GHSA-jg22-mg44-37j8 MODERATE AIOHTTP is Vulnerable to Deserialization of Untrusted Data 1.2.0 3.14.0 -
aiohttp GHSA-qvrw-v9rv-5rjx MODERATE aiohttp's ClientSession is vulnerable to CRLF injection via method 1.2.0 3.9.0 -
aiohttp GHSA-hpj7-wq8m-9hgp MODERATE aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges 1.2.0 3.14.1 -
aiohttp PYSEC-2026-2105 MODERATE - 1.2.0 3.14.0 -
aiohttp CVE-2026-47265 MODERATE AIOHTTP vulnerable to cross-origin redirect with per-request cookies 1.2.0 - -
aiohttp GHSA-hg6j-4rv6-33pg MODERATE AIOHTTP is vulnerable to cross-origin redirect with per-request cookies 1.2.0 3.14.0 -
aiohttp CVE-2025-69228 MODERATE AIOHTTP vulnerable to denial of service through large payloads 1.2.0 - -
aiohttp GHSA-xcgm-r5h9-7989 MODERATE aiohttp: Incomplete websocket frame payloads bypass memory limits 1.2.0 3.14.1 -
aiohttp PYSEC-2026-1103 MODERATE aiohttp allows request smuggling due to incorrect parsing of chunk extensions 1.2.0 3.10.11 -
aiohttp CVE-2024-52304 MODERATE aiohttp vulnerable to request smuggling due to incorrect parsing of chunk extensions 1.2.0 - -
aiohttp GHSA-pjjw-qhg8-p2p9 MODERATE aiohttp has vulnerable dependency that is vulnerable to request smuggling 1.2.0 3.8.6 -
aiohttp GHSA-8495-4g3g-x7pr MODERATE aiohttp allows request smuggling due to incorrect parsing of chunk extensions 1.2.0 3.10.11 -
aiohttp GHSA-w2fm-2cpv-w7v5 MODERATE aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage 1.2.0 3.13.4 -
aiohttp GHSA-g3cq-j2xw-wf74 MODERATE aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup 1.2.0 3.14.1 -
aiohttp GHSA-g84x-mcqj-x9qq MODERATE AIOHTTP vulnerable to DoS through chunked messages 1.2.0 3.13.3 -
aiohttp PYSEC-2026-1106 MODERATE AIOHTTP vulnerable to DoS through chunked messages 1.2.0 3.13.3 -
aiohttp CVE-2025-69229 MODERATE AIOHTTP vulnerable to DoS through chunked messages 1.2.0 - -
aiohttp PYSEC-2026-1100 MODERATE AIOHTTP vulnerable to denial of service through large payloads 1.2.0 3.13.3 -
aiohttp GHSA-6jhg-hg63-jvvf MODERATE AIOHTTP vulnerable to denial of service through large payloads 1.2.0 3.13.3 -
aiohttp PYSEC-2026-3547 MODERATE AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate 1.2.0 3.14.2 -
aiohttp GHSA-4fvr-rgm6-gqmc MODERATE aiohttp: HTTP/1 Pipelined Requests Queue Without Limit 1.2.0 3.14.1 -
aiohttp PYSEC-2026-2107 MODERATE - 1.2.0 3.14.1 -
aiohttp CVE-2026-54273 MODERATE AIOHTTP: HTTP/1 Pipelined Requests Queue Without Limit 1.2.0 - -
aiohttp GHSA-c427-h43c-vf67 MODERATE AIOHTTP accepts duplicate Host headers 1.2.0 3.13.4 -
aiohttp CVE-2026-34525 MODERATE AIOHTTP: Duplicate Host header accepted 1.2.0 - -
aiohttp PYSEC-2026-2103 MODERATE - 1.2.0 3.13.4 -
aiohttp CVE-2026-59881 MODERATE AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate 1.2.0 - -
aiohttp GHSA-mq44-7p77-q5h7 MODERATE AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate 1.2.0 3.14.2 -
aiohttp GHSA-63hw-fmq6-xxg2 MODERATE aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines 1.2.0 3.14.1 -
aiohttp GHSA-gfw2-4jvh-wgfg MODERATE AIOHTTP has problems in HTTP parser (the python one, not llhttp) 1.2.0 3.8.6 -
aiohttp CVE-2023-47627 MODERATE Request smuggling in aiohttp 1.2.0 - -
aiohttp GHSA-q3qx-c6g2-7pw2 MODERATE aiohttp's ClientSession is vulnerable to CRLF injection via version 1.2.0 3.9.0 -
aiohttp CVE-2026-34513 LOW AIOHTTP: Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector 1.2.0 - -
aiohttp CVE-2026-50269 low AIOHTTP: CRLF injection in multipart headers 1.2.0 - -
aiohttp PYSEC-2026-2100 LOW - 1.2.0 3.13.4 -
aiohttp CVE-2023-47641 LOW Inconsistent interpretation of Content-Length vs. Transfer-Encoding in aiohttp 1.2.0 - -
aiohttp GHSA-xx9p-xxvh-7g8j LOW Aiohttp has inconsistent interpretation of Content-Length vs. Transfer-Encoding differing in C and Python fallbacks 1.2.0 3.8.0 -
aiohttp PYSEC-2026-1105 LOW AIOHTTP Vulnerable to Cookie Parser Warning Storm 1.2.0 3.13.3 -
aiohttp PYSEC-2026-2101 LOW - 1.2.0 3.13.4 -
aiohttp CVE-2026-34519 LOW AIOHTTP: HTTP response splitting via \r in reason phrase 1.2.0 - -
aiohttp GHSA-mwh4-6h8g-pg8w LOW AIOHTTP has HTTP response splitting via \r in reason phrase 1.2.0 3.13.4 -
aiohttp PYSEC-2026-2099 low - 1.2.0 3.13.4 -
aiohttp GHSA-3wq7-rqq7-wx6j LOW AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS 1.2.0 3.13.4 -
aiohttp CVE-2026-34517 low AIOHTTP: Late size enforcement for non-file multipart fields causes memory DoS 1.2.0 - -
aiohttp PYSEC-2023-247 LOW - 1.2.0 f016f0680e4ace6742b03a70cb0382ce86abe371 -
aiohttp CVE-2026-54280 LOW AIOHTTP: Payload Response Resources Are Not Closed After Mid-Body Disconnect 1.2.0 - -
aiohttp GHSA-m6qw-4cw2-hm4m LOW aiohttp: CRLF injection in multipart headers 1.2.0 3.14.0 -
aiohttp PYSEC-2026-2095 LOW - 1.2.0 3.13.4 -
aiohttp PYSEC-2026-2106 low - 1.2.0 3.14.0 -
aiohttp PYSEC-2026-2113 LOW - 1.2.0 3.14.1 -
aiohttp PYSEC-2026-2096 low - 1.2.0 3.13.4 -
aiohttp CVE-2026-34514 low AIOHTTP: CRLF injection in multipart part content type header construction 1.2.0 - -
aiohttp GHSA-2vrm-gr82-f7m5 LOW AIOHTTP has CRLF injection through multipart part content type header construction 1.2.0 3.13.4 -
aiohttp GHSA-hcc4-c3v8-rx92 LOW AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector 1.2.0 3.13.4 -
aiohttp CVE-2026-34518 LOW AIOHTTP: Cookie and Proxy-Authorization headers leaked on cross-origin redirect 1.2.0 - -
aiohttp GHSA-966j-vmvw-g2g9 LOW AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect 1.2.0 3.13.4 -
aiohttp GHSA-54jq-c3m8-4m76 LOW AIOHTTP vulnerable to brute-force leak of internal static file path components 1.2.0 3.13.3 -
aiohttp GHSA-9x8q-7h8h-wcw9 LOW aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnect 1.2.0 3.14.1 -
aiohttp GHSA-63hf-3vf5-4wqf LOW AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass 1.2.0 3.13.4 -
aiohttp GHSA-2fqr-mr3j-6wp8 LOW aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence 1.2.0 3.14.1 -
aiohttp CVE-2026-54279 LOW AIOHTTP: Host-Only Cookies Become Domain Cookies After CookieJar Persistence 1.2.0 - -
aiohttp PYSEC-2026-2112 LOW - 1.2.0 3.14.1 -
aiohttp PYSEC-2021-76 LOW - 1.2.0 2545222a3853e31ace15d87ae0e2effb7da0c96b -
aiohttp GHSA-69f9-5gxw-wvc2 LOW AIOHTTP's unicode processing of header values could cause parsing discrepancies 1.2.0 3.13.3 -
aiohttp CVE-2021-21330 LOW - 1.2.0 - -
aiohttp GHSA-fh55-r93g-j68g LOW AIOHTTP Vulnerable to Cookie Parser Warning Storm 1.2.0 3.13.3 -
aiohttp PYSEC-2026-1104 LOW AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections 1.2.0 3.12.14 -
aiohttp CVE-2025-53643 LOW AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections 1.2.0 - -
aiohttp GHSA-v6wp-4m6f-gcjg LOW aiohttp Open Redirect vulnerability (normalize_path_middleware middleware) 1.2.0 3.7.4 -
aiohttp GHSA-9548-qrrj-x5pj LOW AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections 1.2.0 3.12.14 -
aiohttp CVE-2025-69230 LOW AIOHTTP Vulnerable to Cookie Parser Warning Storm 1.2.0 - -
aiohttp PYSEC-2026-1109 low AIOHTTP has unicode match groups in regexes for ASCII protocol elements 1.2.0 3.13.3 -
aiohttp CVE-2025-69225 low AIOHTTP Regex Mismatch Allows Unicode in ASCII-Only Protocol Fields 1.2.0 - -
aiohttp GHSA-mqqc-3gqh-h2x8 LOW AIOHTTP has unicode match groups in regexes for ASCII protocol elements 1.2.0 3.13.3 -
aiohttp GHSA-4m7w-qmgq-4wj5 LOW aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections 1.2.0 3.14.1 -
aiohttp CVE-2026-54275 LOW AIOHTTP: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections 1.2.0 - -
aiohttp PYSEC-2026-237 LOW - 1.2.0 3.14.1 -
⚠️ Dependencies that have Reached EOL (1)
Dependency Unsafe Version EOL Date New Version Path Case
aiohttp 1.2.0 - 3.14.3 python/aiohttp/simple_app/requirements.txt -

Review Checklist

Extra review is recommended for this update:

  • Review changes for compatibility with your code
  • Check release notes for breaking changes
  • Run integration tests to verify service behavior
  • Test in staging environment before production
  • Monitor key metrics after deployment
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants