Skip to content

Fix for GHSA-cq5v-8q36-5273 - #327

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
socket/fix/GHSA-cq5v-8q36-5273
Open

github-actions[bot] wants to merge 1 commit into
mainfrom
socket/fix/GHSA-cq5v-8q36-5273

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Socket fix for GHSA-cq5v-8q36-5273.

Vulnerability Summary: AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)

Severity: HIGH

Affected Packages: aiohttp (PIP)

… response parser error path (malformed chunked response)
@github-actions
github-actions Bot enabled auto-merge (squash) September 21, 2026 06:53
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedpypi/​aiohttp@​3.14.1 ⏵ 3.14.397 +1100 +19100100100

View full report

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants