Skip to content

GHSA-cq5v-8q36-5273 on CTRL-OS 26.05

Aliases: GHSA-cq5v-8q36-5273

Packages: python3Packages.aiohttp

Status: Plausible

Advisory Information

Summary

An out-of-bounds heap read could occur in the C response parser while building an error message for a malformed response.

Impact

An attacker controlled server, or possibly an accidental response could trigger a DoS in the client.

Workaround

If unable to upgrade, the Python parser is unaffected and can be used with AIOHTTP_NO_EXTENSIONS=1.


Patch: https://github.com/aio-libs/aiohttp/commit/49f65d54150397892f7bcc4aae887767d51c322d

Updates

2026-07-27 23:21 CEST

Metadata changes:

  • Status for package python3Packages.aiohttp: “Plausible

2026-07-27 18:50 CEST

Metadata changes:

  • Status for package python3Packages.aiohttp: “New