[Git][security-tracker-team/security-tracker][master] Add CVE-2026-59881/python-aiohttp

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jul 30 21:29:02 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ca1308cd by Salvatore Bonaccorso at 2026-07-30T22:28:42+02:00
Add CVE-2026-59881/python-aiohttp

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -37,7 +37,11 @@ CVE-2026-5582 (The FuseWP plugin for WordPress is vulnerable to Cross-Site Reque
 CVE-2026-5219 (Cross-Site request forgery (CSRF) vulnerability in Softtr Information  ...)
 	NOT-FOR-US: E-Commerce Pack
 CVE-2026-59881 (AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...)
-	TODO: check
+	- python-aiohttp <unfixed>
+	[trixie] - python-aiohttp <no-dsa> (Minor issue)
+	NOTE: https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mq44-7p77-q5h7
+	NOTE: https://github.com/aio-libs/aiohttp/pull/12978
+	NOTE: Fixed by: https://github.com/aio-libs/aiohttp/commit/47fb6ae354d4fa22048f4dbe7dbf82b625f0a2f6 (v3.14.2)
 CVE-2026-59310 (VMware vCenter contains a directory traversal vulnerability in the Sys ...)
 	NOT-FOR-US: VMware
 CVE-2026-59309 (VMware vCenter contains an authentication bypass vulnerability in the  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ca1308cdc4f067b1ec9b3427e000cb083c0d0726

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ca1308cdc4f067b1ec9b3427e000cb083c0d0726
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260730/f136afae/attachment.htm>


More information about the debian-security-tracker-commits mailing list