#1143160 python-aiohttp: CVE-2026-59881

Package:
src:python-aiohttp
Source:
src:python-aiohttp
Submitter:
Salvatore Bonaccorso
Date:
2026-09-12 00:07:01 UTC
Severity:
normal
Tags:
#1143160#5
Date:
2026-07-31 05:29:14 UTC
From:
To:
Hi,

The following vulnerability was published for python-aiohttp.

CVE-2026-59881[0]:
| AIOHTTP is an asynchronous HTTP client/server framework for asyncio
| and Python. Prior to 3.14.2, the WebSocket client accepts and
| decompresses frames with the RSV1 bit set even when the permessage-
| deflate extension was not negotiated, allowing a malicious server to
| cause unexpected CPU and memory consumption. This issue is fixed in
| version 3.14.2.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-59881
https://www.cve.org/CVERecord?id=CVE-2026-59881
[1] https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mq44-7p77-q5h7
[2] https://github.com/aio-libs/aiohttp/pull/12978
[3] https://github.com/aio-libs/aiohttp/commit/47fb6ae354d4fa22048f4dbe7dbf82b625f0a2f6

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1143160#10
Date:
2026-09-12 00:04:52 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
python-aiohttp, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1143160@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Daniel Leidert <dleidert@debian.org> (supplier of updated python-aiohttp package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 02 Sep 2026 20:38:13 +0200
Source: python-aiohttp
Architecture: source
Version: 3.14.3-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <team+python@tracker.debian.org>
Changed-By: Daniel Leidert <dleidert@debian.org>
Closes: 1143160 1143597
Changes:
 python-aiohttp (3.14.3-1) unstable; urgency=medium
 .
   * Team upload.
   * New upstream release.
     - Fix CVE-2026-59881 (closes: #1143160).
     - Fix CVE-2026-69243, CVE-2026-69244 (closes: #1143597).
Checksums-Sha1:
 496b376e210bc7e66b904516f836ab3c33e73242 3064 python-aiohttp_3.14.3-1.dsc
 c35ce3268327bdb9d7ec50396707e332e5028057 7971213 python-aiohttp_3.14.3.orig.tar.gz
 ca69faeeb8647403c049add06ea43c79b1f64e9b 10924 python-aiohttp_3.14.3-1.debian.tar.xz
 eb914ec3de7dcdb55ab4e432536a39eca31b92ad 8764 python-aiohttp_3.14.3-1_source.buildinfo
Checksums-Sha256:
 e6d6f53410f310934ede57274ee7a9e5fced869b4ca4ce0083ce23bcd41625e8 3064 python-aiohttp_3.14.3-1.dsc
 9491196535a88924a60afd5b5f434b5b203b6cc616250878dbdb223a8f7844bc 7971213 python-aiohttp_3.14.3.orig.tar.gz
 8be7db1fd02286a35d9e1952119a6750aa09b0ef5a992665f3f08abebb7f2ac4 10924 python-aiohttp_3.14.3-1.debian.tar.xz
 e76af4f045a37984296f2571106d469f5e1f7d8fba1a15358af5aa0e1a66051d 8764 python-aiohttp_3.14.3-1_source.buildinfo
Files:
 b944a90609bfc681f6530a51d7ba548d 3064 python optional python-aiohttp_3.14.3-1.dsc
 1befc420af8c5cc860a80a629d66cb00 7971213 python optional python-aiohttp_3.14.3.orig.tar.gz
 d366e518a9aff0398be36a653ce886c3 10924 python optional python-aiohttp_3.14.3-1.debian.tar.xz
 9bdeb5e6083b80c57e6c3917a09dabad 8764 python optional python-aiohttp_3.14.3-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEvu1N7VVEpMA+KD3HS80FZ8KW0F0FAmqkkv8ACgkQS80FZ8KW
0F3REA/+JFD/brsKxk362AAVJfrhxXwyPFbvEAeKglAyNhsFMc7iyt+pnWULtoPe
PZh0mWDSGMz92qWRm6j7lVGwzdSQBN/YbClr0QSvAm43fGEFtyYWJsR9agCz/98f
RXIzJ9BbNR4UxUTmPZqfzc2v6YRRRf+DDs3W6D4nM4bUeWchTNz0S9krBtUpgFo+
3rEgQL480pWRWpKaUaRvSTkLv9eBUw2uZmRCo+Av2tcprHNfrRcu85msg535FPCc
YSI1xqW4YxA5JJc3IO9WsdhBZyywI+Qvt4cqhIaTeAGKGGrG8W2eQfMxUvVFzdrj
nrOHIc22wQW6An9GtTM/eKMP2jQJsK5vzVBAoUnyLXwDf9Bf5UXlOAq/1YZuFbEg
GkYvaPMec3Nfhg2QILLMqxRYe4jPHGzKuP1yfuLZM34r3lym76H5wvV2tz7IV4O2
g2csqEbRrdlj1OtGoFLKU2nwSrisWH67mzV9mF+qhqpBN/7kvY/0nb+l0szaCvHD
Ci+u9iM0gzqxw/0mz3l+ZRqUIbEJzItjiwM10GHGHc3QKbyANHvvorICoeUVoVYx
dw67EzDpgUzS0Cw65wKjlSlOQfseoUKwfbfuWDtBYvGsXvbnccBRm5V8N4n1PjIP
vguO63uhWYZ9tRLzA60zTURZlmWWXg2nWHWS889zJ4zF470nb0c=
=RJlE
-----END PGP SIGNATURE-----