- Package:
- src:python-aiohttp
- Source:
- src:python-aiohttp
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-09-12 00:07:02 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerabilities were published for python-aiohttp. CVE-2026-69243[0]: | AIOHTTP is an asynchronous HTTP client/server framework for asyncio | and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a | request smuggling attack relating to WebSocket upgrades. If using | the server-side component, an attacker may be able to execute a | request smuggling vulnerability using an edge case in the WebSocket | upgrade procedure. A WebSocket upgrade request with a body could | cause the parser to switch protocols before the complete request | body was received, leaving trailing bytes to be handled as upgraded- | protocol or pipelined data rather than normal HTTP body data. This | issue is fixed in version 3.14.2. CVE-2026-69244[1]: | AIOHTTP is an asynchronous HTTP client/server framework for asyncio | and Python. Prior to 3.14.3, an out-of-bounds heap read could occur | in the C response parser while building an error message for a | malformed response. An attacker controlled server, or possibly an | accidental response, could trigger a DoS in the client. The | vulnerable path was error message construction in | aiohttp/_http_parser.pyx, where an llhttp error-position pointer was | used to build a snippet for malformed chunked responses and | malformed request or response bytes at the buffer end. This issue is | fixed in version 3.14.3. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-69243 https://www.cve.org/CVERecord?id=CVE-2026-69243 [1] https://security-tracker.debian.org/tracker/CVE-2026-69244 https://www.cve.org/CVERecord?id=CVE-2026-69244 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
python-aiohttp, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1143597@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Daniel Leidert <dleidert@debian.org> (supplier of updated python-aiohttp package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 02 Sep 2026 20:38:13 +0200
Source: python-aiohttp
Architecture: source
Version: 3.14.3-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <team+python@tracker.debian.org>
Changed-By: Daniel Leidert <dleidert@debian.org>
Closes: 1143160 1143597
Changes:
python-aiohttp (3.14.3-1) unstable; urgency=medium
.
* Team upload.
* New upstream release.
- Fix CVE-2026-59881 (closes: #1143160).
- Fix CVE-2026-69243, CVE-2026-69244 (closes: #1143597).
Checksums-Sha1:
496b376e210bc7e66b904516f836ab3c33e73242 3064 python-aiohttp_3.14.3-1.dsc
c35ce3268327bdb9d7ec50396707e332e5028057 7971213 python-aiohttp_3.14.3.orig.tar.gz
ca69faeeb8647403c049add06ea43c79b1f64e9b 10924 python-aiohttp_3.14.3-1.debian.tar.xz
eb914ec3de7dcdb55ab4e432536a39eca31b92ad 8764 python-aiohttp_3.14.3-1_source.buildinfo
Checksums-Sha256:
e6d6f53410f310934ede57274ee7a9e5fced869b4ca4ce0083ce23bcd41625e8 3064 python-aiohttp_3.14.3-1.dsc
9491196535a88924a60afd5b5f434b5b203b6cc616250878dbdb223a8f7844bc 7971213 python-aiohttp_3.14.3.orig.tar.gz
8be7db1fd02286a35d9e1952119a6750aa09b0ef5a992665f3f08abebb7f2ac4 10924 python-aiohttp_3.14.3-1.debian.tar.xz
e76af4f045a37984296f2571106d469f5e1f7d8fba1a15358af5aa0e1a66051d 8764 python-aiohttp_3.14.3-1_source.buildinfo
Files:
b944a90609bfc681f6530a51d7ba548d 3064 python optional python-aiohttp_3.14.3-1.dsc
1befc420af8c5cc860a80a629d66cb00 7971213 python optional python-aiohttp_3.14.3.orig.tar.gz
d366e518a9aff0398be36a653ce886c3 10924 python optional python-aiohttp_3.14.3-1.debian.tar.xz
9bdeb5e6083b80c57e6c3917a09dabad 8764 python optional python-aiohttp_3.14.3-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEvu1N7VVEpMA+KD3HS80FZ8KW0F0FAmqkkv8ACgkQS80FZ8KW
0F3REA/+JFD/brsKxk362AAVJfrhxXwyPFbvEAeKglAyNhsFMc7iyt+pnWULtoPe
PZh0mWDSGMz92qWRm6j7lVGwzdSQBN/YbClr0QSvAm43fGEFtyYWJsR9agCz/98f
RXIzJ9BbNR4UxUTmPZqfzc2v6YRRRf+DDs3W6D4nM4bUeWchTNz0S9krBtUpgFo+
3rEgQL480pWRWpKaUaRvSTkLv9eBUw2uZmRCo+Av2tcprHNfrRcu85msg535FPCc
YSI1xqW4YxA5JJc3IO9WsdhBZyywI+Qvt4cqhIaTeAGKGGrG8W2eQfMxUvVFzdrj
nrOHIc22wQW6An9GtTM/eKMP2jQJsK5vzVBAoUnyLXwDf9Bf5UXlOAq/1YZuFbEg
GkYvaPMec3Nfhg2QILLMqxRYe4jPHGzKuP1yfuLZM34r3lym76H5wvV2tz7IV4O2
g2csqEbRrdlj1OtGoFLKU2nwSrisWH67mzV9mF+qhqpBN/7kvY/0nb+l0szaCvHD
Ci+u9iM0gzqxw/0mz3l+ZRqUIbEJzItjiwM10GHGHc3QKbyANHvvorICoeUVoVYx
dw67EzDpgUzS0Cw65wKjlSlOQfseoUKwfbfuWDtBYvGsXvbnccBRm5V8N4n1PjIP
vguO63uhWYZ9tRLzA60zTURZlmWWXg2nWHWS889zJ4zF470nb0c=
=RJlE
-----END PGP SIGNATURE-----