Source: python-aiohttp
Version: 3.14.1-4
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for python-aiohttp.

CVE-2026-69243[0]:
| AIOHTTP is an asynchronous HTTP client/server framework for asyncio
| and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a
| request smuggling attack relating to WebSocket upgrades. If using
| the server-side component, an attacker may be able to execute a
| request smuggling vulnerability using an edge case in the WebSocket
| upgrade procedure. A WebSocket upgrade request with a body could
| cause the parser to switch protocols before the complete request
| body was received, leaving trailing bytes to be handled as upgraded-
| protocol or pipelined data rather than normal HTTP body data. This
| issue is fixed in version 3.14.2.


CVE-2026-69244[1]:
| AIOHTTP is an asynchronous HTTP client/server framework for asyncio
| and Python. Prior to 3.14.3, an out-of-bounds heap read could occur
| in the C response parser while building an error message for a
| malformed response. An attacker controlled server, or possibly an
| accidental response, could trigger a DoS in the client. The
| vulnerable path was error message construction in
| aiohttp/_http_parser.pyx, where an llhttp error-position pointer was
| used to build a snippet for malformed chunked responses and
| malformed request or response bytes at the buffer end. This issue is
| fixed in version 3.14.3.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-69243
    https://www.cve.org/CVERecord?id=CVE-2026-69243
[1] https://security-tracker.debian.org/tracker/CVE-2026-69244
    https://www.cve.org/CVERecord?id=CVE-2026-69244

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to