[Git][security-tracker-team/security-tracker][master] Add two new python-aiohttp issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 4 09:51:05 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
06d622c8 by Salvatore Bonaccorso at 2026-08-04T10:50:43+02:00
Add two new python-aiohttp issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -33,9 +33,15 @@ CVE-2026-69245 (Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0
 	NOTE: Fixed by: https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4 (8.0.1)
 	NOTE: Fixed by: https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf (7.15.2)
 CVE-2026-69244 (AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...)
-	TODO: check
+	- python-aiohttp <unfixed>
+	NOTE: https://github.com/aio-libs/aiohttp/security/advisories/GHSA-cq5v-8q36-5273
+	NOTE: https://github.com/aio-libs/aiohttp/pull/13223
+	NOTE: Fixed by: https://github.com/aio-libs/aiohttp/commit/49f65d54150397892f7bcc4aae887767d51c322d (v3.14.3)
 CVE-2026-69243 (AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...)
-	TODO: check
+	- python-aiohttp <unfixed>
+	NOTE: https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mfx4-hv73-q22v
+	NOTE: https://github.com/aio-libs/aiohttp/pull/13017
+	NOTE: Fixed by: https://github.com/aio-libs/aiohttp/commit/6ae358f0983c3f4d6f67692b2f8e65dc8e091c98 (v3.14.2)
 CVE-2026-69240 (Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is pos ...)
 	TODO: check
 CVE-2026-69198 (ip-address is a library for parsing and manipulating IPv4 and IPv6 add ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/06d622c860caa6c919fe710d67686a6bf0807b2d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/06d622c860caa6c919fe710d67686a6bf0807b2d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260804/a9d0f501/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list