Skip to content

chore(deps): update dependency aiohttp to v3.14.3 [security] - autoclosed - #1984

Closed
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/pypi-aiohttp-vulnerability
Closed

chore(deps): update dependency aiohttp to v3.14.3 [security] - autoclosed#1984
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/pypi-aiohttp-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Aug 4, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change OpenSSF
aiohttp patch ==3.14.1==3.14.3 OpenSSF Scorecard

AIOHTTP: HTTP request smuggling via WebSocket upgrade

CVE-2026-69243 / GHSA-mfx4-hv73-q22v

More information

Details

Summary

The HTTP parsers were vulnerable to a request smuggling attack relating to WebSocket upgrades.

Impact

If using the server-side component, it may be possible for an attacker to execute a request smuggling vulnerability using an edge case in the WebSocket upgrade procedure. AIOHTT is unaware of any public exploit code.


Patch: aio-libs/aiohttp@6ae358f

Severity

  • CVSS Score: 6.3 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate

CVE-2026-59881 / GHSA-mq44-7p77-q5h7

More information

Details

Summary

The client accepts and decompresses frames with the RSV1 bit set even when the permessage-deflate extension was not negotiated.

Impact

A client may unexpectedly decompress WebSocket frames when explicitly opted out. This could lead to additional CPU/memory consumption, but is unlikely to be a significant issue unless a zip bomb vulnerability or similar is also present.


Patch: aio-libs/aiohttp@47fb6ae

Severity

  • CVSS Score: 6.9 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)

CVE-2026-69244 / GHSA-cq5v-8q36-5273

More information

Details

Summary

An out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response.

Impact

An attacker controlled server, or possibly an accidental response could trigger a DoS in the client.

Workaround

If unable to upgrade, the Python parser is unaffected and can be used with AIOHTTP_NO_EXTENSIONS=1.


Patch: aio-libs/aiohttp@49f65d5

Severity

  • CVSS Score: 7.1 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

aio-libs/aiohttp (aiohttp)

v3.14.3

Compare Source

===================

Bug fixes

  • Fixed the client dropping only the first Authorization, Cookie and
    Proxy-Authorization header when a redirect crossed an origin -- by :user:arshsmith1.

    Related issues and pull requests on GitHub:
    :issue:13180.

  • Fixed error message construction in the C HTTP parser -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:13222.


v3.14.2

Compare Source

===================

Bug fixes

  • Fixed :py:attr:~aiohttp.web.StreamResponse.last_modified rounding a
    :class:datetime.datetime with a fractional second down.

    Related issues and pull requests on GitHub:
    :issue:5303.

  • Fixed resolving localhost on Windows to fall back without AI_ADDRCONFIG
    when the first lookup fails, so localhost still works without an active
    network.

    Related issues and pull requests on GitHub:
    :issue:5357.

  • Rejected multipart body parts whose Content-Length header is not a
    plain sequence of digits (e.g. +5, -1, 1_0), matching the
    strictness of the main request parser per :rfc:9110#section-8.6
    -- by :user:dxbjavid.

    Related issues and pull requests on GitHub:
    :issue:12794.

  • Fixed GunicornWebWorker endlessly reloading when app fails during startup -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:12879.

  • Fixed some inconsistent case sensitivity on request methods -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:12931.

  • Fixed IndexError: string index out of range in parse_content_disposition
    when a header parameter has an empty value (e.g. filename=).
    -- by :user:JSap0914.

    Related issues and pull requests on GitHub:
    :issue:12948.

  • Fixed the sock_read timeout being re-armed on a keep-alive connection after
    it had been returned to the pool. An idle pooled connection could be left with a
    pending read timeout that fired and poisoned it, so the next request reusing the
    connection failed immediately with :exc:aiohttp.SocketTimeoutError. The read
    timeout is now only rescheduled when resuming a transport that was actually
    paused -- by :user:daragok.

    Related issues and pull requests on GitHub:
    :issue:12953, :issue:12954.

  • Fixed the client decompressing frames when permessage-deflate was not negotiated -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:12976.

  • Fixed DigestAuthMiddleware raising an IndexError on empty domain -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:12983.

  • Fixed :class:~aiohttp.DigestAuthMiddleware corrupting the Digest
    challenge when a WWW-Authenticate response offered more than one
    authentication scheme -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:12984.

  • Fixed client not closing cleanly after an exception -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:12985.

  • Fixed control frames breaking fragmented WebSocket messages -- by :user:arshsmith1.

    Related issues and pull requests on GitHub:
    :issue:12988.

  • Fixed parse_content_disposition rejecting otherwise-valid
    Content-Disposition header values that contain optional whitespace (OWS)
    around the disposition type (e.g. "form-data ; name=\"field\"").
    The disposition type is now stripped before token validation, consistent with
    how parameter keys are already handled -- by :user:JSap0914.

    Related issues and pull requests on GitHub:
    :issue:12996.

  • Fixed an :exc:IndexError in the pure-Python HTTP parser -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13001.

  • Fixed parsing optional whitespace in Content-Disposition -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13002.

  • Fixed request body not being read on rejected WebSocket upgrades -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13016.

  • Fixed :exc:LookupError (and an unguarded :exc:UnicodeDecodeError) escaping
    Content-Disposition parsing when a multipart part supplies an extended
    parameter with an unknown charset
    -- by :user:arshsmith1.

    Related issues and pull requests on GitHub:
    :issue:13042.

  • Fixed escape_quotes in the Digest authentication middleware not escaping
    backslashes, so a WWW-Authenticate challenge value containing a backslash
    could break out of its quoted-string in the generated Authorization header
    -- by :user:dxbjavid.

    Related issues and pull requests on GitHub:
    :issue:13054.

  • Fixed Python parser not rejecting a bare LF in the request line -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13136.

  • Fixed the C HTTP parser folding the fragment into the query string for an
    origin-form request target with an empty query (e.g. /path?#frag),
    which diverged from the pure-Python parser -- by :user:GiulioDER.

    Related issues and pull requests on GitHub:
    :issue:13171.

  • Fixed the C parser reporting newer HTTP methods such as QUERY as <unknown>;
    the method table is now derived from the vendored llhttp instead of a hand-maintained count
    -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:13174.

Packaging updates and notes for downstreams

  • Upgraded llhttp to v9.4.2 -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:12956.

Contributor-facing changes

  • Added admin documentation on incident response and on running reproducer code
    safely, covering security vulnerability handling and supply-chain, account, and
    CI/infrastructure compromise -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    :issue:12914.



Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot temporarily deployed to Vespa Cloud CD August 4, 2026 02:19 Inactive
@renovate
renovate Bot force-pushed the renovate/pypi-aiohttp-vulnerability branch from eccfcd7 to b93b291 Compare August 4, 2026 07:13
@renovate
renovate Bot temporarily deployed to Vespa Cloud CD August 4, 2026 07:14 Inactive
@renovate renovate Bot changed the title chore(deps): update dependency aiohttp to v3.14.3 [security] chore(deps): update dependency aiohttp to v3.14.3 [security] - autoclosed Aug 4, 2026
@renovate renovate Bot closed this Aug 4, 2026
@renovate
renovate Bot deleted the renovate/pypi-aiohttp-vulnerability branch August 4, 2026 09:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants