Skip to content

Fix for GHSA-mfx4-hv73-q22v - #328

Open
github-actions[bot] wants to merge 1 commit into
mainfrom
socket/fix/GHSA-mfx4-hv73-q22v
Open

github-actions[bot] wants to merge 1 commit into
mainfrom
socket/fix/GHSA-mfx4-hv73-q22v

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Socket fix for GHSA-mfx4-hv73-q22v.

Vulnerability Summary: AIOHTTP: HTTP request smuggling via WebSocket upgrade

Severity: MODERATE

Affected Packages: aiohttp (PIP)

@github-actions
github-actions Bot enabled auto-merge (squash) September 21, 2026 06:53
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedpypi/​aiohttp@​3.14.1 ⏵ 3.14.297 +185 +3100100100

View full report

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants