Skip to content

chore(deps): bump aiohttp to 3.14.3 (fixes 3 Dependabot alerts) - #863

Merged
neoneye merged 1 commit into
mainfrom
security/aiohttp-3.14.3
Aug 29, 2026
Merged

neoneye merged 1 commit into
mainfrom
security/aiohttp-3.14.3

Conversation

@neoneye

@neoneye neoneye commented Aug 29, 2026

Copy link
Copy Markdown
Member

Bumps aiohttp in worker_plan/pyproject.toml from 3.14.1 to 3.14.3.

Closes the three open Dependabot alerts on the repo:

Alert Severity Advisory
#195 high GHSA-cq5v-8q36-5273 — out-of-bounds heap read in the C HTTP response parser error path (malformed chunked response)
#194 medium GHSA-mfx4-hv73-q22v — HTTP request smuggling via WebSocket upgrade
#193 medium GHSA-mq44-7p77-q5h7 — WebSocket client accepts compressed frames without negotiated permessage-deflate

3.14.3 is the first stable release patched against all three (currently the latest aiohttp release).

Resolves three open Dependabot alerts against worker_plan: GHSA-cq5v-8q36-5273 (high, out-of-bounds heap read in the C HTTP response parser error path), GHSA-mfx4-hv73-q22v (request smuggling via WebSocket upgrade), and GHSA-mq44-7p77-q5h7 (WebSocket client accepting compressed frames without negotiated permessage-deflate).

3.14.3 is the first release patched against all three.
@neoneye
neoneye merged commit 74df0cc into main Aug 29, 2026
3 checks passed
@neoneye
neoneye deleted the security/aiohttp-3.14.3 branch August 29, 2026 12:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant