[Git][security-tracker-team/security-tracker][master] Track fixes for python-aiohttp via unstable
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 12 06:59:56 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
13cb97a6 by Salvatore Bonaccorso at 2026-09-12T07:59:25+02:00
Track fixes for python-aiohttp via unstable
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -46665,13 +46665,13 @@ CVE-2026-69245 (Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0
NOTE: Fixed by: https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4 (8.0.1)
NOTE: Fixed by: https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf (7.15.2)
CVE-2026-69244 (AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...)
- - python-aiohttp <unfixed> (bug #1143597)
+ - python-aiohttp 3.14.3-1 (bug #1143597)
[trixie] - python-aiohttp <no-dsa> (Minor issue)
NOTE: https://github.com/aio-libs/aiohttp/security/advisories/GHSA-cq5v-8q36-5273
NOTE: https://github.com/aio-libs/aiohttp/pull/13223
NOTE: Fixed by: https://github.com/aio-libs/aiohttp/commit/49f65d54150397892f7bcc4aae887767d51c322d (v3.14.3)
CVE-2026-69243 (AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...)
- - python-aiohttp <unfixed> (bug #1143597)
+ - python-aiohttp 3.14.3-1 (bug #1143597)
[trixie] - python-aiohttp <no-dsa> (Minor issue)
NOTE: https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mfx4-hv73-q22v
NOTE: https://github.com/aio-libs/aiohttp/pull/13017
@@ -48858,7 +48858,7 @@ CVE-2026-5582 (The FuseWP plugin for WordPress is vulnerable to Cross-Site Reque
CVE-2026-5219 (Cross-Site request forgery (CSRF) vulnerability in Softtr Information ...)
NOT-FOR-US: E-Commerce Pack
CVE-2026-59881 (AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...)
- - python-aiohttp <unfixed> (bug #1143160)
+ - python-aiohttp 3.14.3-1 (bug #1143160)
[trixie] - python-aiohttp <no-dsa> (Minor issue)
NOTE: https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mq44-7p77-q5h7
NOTE: https://github.com/aio-libs/aiohttp/pull/12978
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/13cb97a61e9e9d6818435666078ebc18c1289bb6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/13cb97a61e9e9d6818435666078ebc18c1289bb6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260912/2ad9b0e1/attachment.htm>
More information about the debian-security-tracker-commits
mailing list