[Git][security-tracker-team/security-tracker][master] Add CVE-2026-59881/python-aiohttp
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Jul 30 21:29:02 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
ca1308cd by Salvatore Bonaccorso at 2026-07-30T22:28:42+02:00
Add CVE-2026-59881/python-aiohttp
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -37,7 +37,11 @@ CVE-2026-5582 (The FuseWP plugin for WordPress is vulnerable to Cross-Site Reque
CVE-2026-5219 (Cross-Site request forgery (CSRF) vulnerability in Softtr Information ...)
NOT-FOR-US: E-Commerce Pack
CVE-2026-59881 (AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...)
- TODO: check
+ - python-aiohttp <unfixed>
+ [trixie] - python-aiohttp <no-dsa> (Minor issue)
+ NOTE: https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mq44-7p77-q5h7
+ NOTE: https://github.com/aio-libs/aiohttp/pull/12978
+ NOTE: Fixed by: https://github.com/aio-libs/aiohttp/commit/47fb6ae354d4fa22048f4dbe7dbf82b625f0a2f6 (v3.14.2)
CVE-2026-59310 (VMware vCenter contains a directory traversal vulnerability in the Sys ...)
NOT-FOR-US: VMware
CVE-2026-59309 (VMware vCenter contains an authentication bypass vulnerability in the ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ca1308cdc4f067b1ec9b3427e000cb083c0d0726
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ca1308cdc4f067b1ec9b3427e000cb083c0d0726
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260730/f136afae/attachment.htm>
More information about the debian-security-tracker-commits
mailing list