Skip to content

fix(deps): vuln minor upgrades — 4 packages (minor: 4) [samples/openapi3] - #48

Closed
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/minorpatch/pip/openapi3/2-1781594209
Closed

fix(deps): vuln minor upgrades — 4 packages (minor: 4) [samples/openapi3]#48
gh-worker-campaigns-3e9aa4[bot] wants to merge 1 commit into
masterfrom
engraver-auto-version-upgrade/minorpatch/pip/openapi3/2-1781594209

Conversation

@gh-worker-campaigns-3e9aa4

Copy link
Copy Markdown

Summary: High-severity security update — 12 packages upgraded (MINOR changes included)

Manifests changed:

  • samples/openapi3 (pip)

✅ Action Required: Please review the changes below. If they look good, approve and merge this PR.


Updates

Package From To Type Dep Type Vulnerabilities Fixed
aiohttp 3.0.0 3.14.1 minor Direct 7 HIGH, 37 MEDIUM, 26 LOW
aiohttp 3.0.0 3.14.1 minor Direct 7 HIGH, 37 MEDIUM, 26 LOW
pycryptodome 3.9.0 3.23.0 minor Direct 3 HIGH
pycryptodome 3.9.0 3.23.0 minor Direct 3 HIGH
pycryptodome 3.9.0 3.23.0 minor Direct 3 HIGH
pycryptodome 3.9.0 3.23.0 minor Direct 3 HIGH
pydantic 2 2.13.4 minor Direct 2 MEDIUM
pydantic 2 2.13.4 minor Direct 2 MEDIUM
pytest 7.1.3 7.4.4 minor Direct 2 MEDIUM
pytest 7.1.3 7.4.4 minor Direct 2 MEDIUM
pytest 7.1.3 7.4.4 minor Direct 2 MEDIUM
pytest 7.1.3 7.4.4 minor Direct 2 MEDIUM

Security Details

🚨 Critical & High Severity (26 fixed)
Package CVE Severity Summary Unsafe Version Fixed In
aiohttp GHSA-5h86-8mv2-jq9f HIGH aiohttp is vulnerable to directory traversal 3.0.0 3.9.2
aiohttp CVE-2024-23334 HIGH aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal 3.0.0 -
aiohttp PYSEC-2024-24 HIGH - 3.0.0 1c335944d6a8b1298baf179b7c0b3069f10c514b
aiohttp CVE-2025-69223 HIGH AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb 3.0.0 -
aiohttp GHSA-6mq8-rvhq-8wgg HIGH AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb 3.0.0 3.13.3
aiohttp CVE-2024-30251 HIGH Denial of service when trying to parse malformed POST requests in aiohttp 3.0.0 -
aiohttp GHSA-5m98-qgg9-wh84 HIGH aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests 3.0.0 3.9.4
aiohttp PYSEC-2024-24 HIGH - 3.0.0 1c335944d6a8b1298baf179b7c0b3069f10c514b
aiohttp CVE-2025-69223 HIGH AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb 3.0.0 -
aiohttp GHSA-6mq8-rvhq-8wgg HIGH AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb 3.0.0 3.13.3
aiohttp GHSA-5m98-qgg9-wh84 HIGH aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests 3.0.0 3.9.4
aiohttp GHSA-5h86-8mv2-jq9f HIGH aiohttp is vulnerable to directory traversal 3.0.0 3.9.2
aiohttp CVE-2024-30251 HIGH Denial of service when trying to parse malformed POST requests in aiohttp 3.0.0 -
aiohttp CVE-2024-23334 HIGH aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal 3.0.0 -
pycryptodome PYSEC-2024-3 HIGH - 3.9.0 -
pycryptodome CVE-2023-52323 HIGH - 3.9.0 -
pycryptodome GHSA-j225-cvw7-qrx7 HIGH PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption 3.9.0 3.19.1
pycryptodome CVE-2023-52323 HIGH - 3.9.0 -
pycryptodome PYSEC-2024-3 HIGH - 3.9.0 -
pycryptodome GHSA-j225-cvw7-qrx7 HIGH PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption 3.9.0 3.19.1
pycryptodome PYSEC-2024-3 HIGH - 3.9.0 -
pycryptodome GHSA-j225-cvw7-qrx7 HIGH PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption 3.9.0 3.19.1
pycryptodome CVE-2023-52323 HIGH - 3.9.0 -
pycryptodome GHSA-j225-cvw7-qrx7 HIGH PyCryptodome and pycryptodomex side-channel leakage for OAEP decryption 3.9.0 3.19.1
pycryptodome CVE-2023-52323 HIGH - 3.9.0 -
pycryptodome PYSEC-2024-3 HIGH - 3.9.0 -
ℹ️ Other Vulnerabilities (138)
Package CVE Severity Summary Unsafe Version Fixed In
aiohttp CVE-2023-49082 medium aiohttp's ClientSession is vulnerable to CRLF injection via method 3.0.0 -
aiohttp CVE-2024-23829 medium aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators 3.0.0 -
aiohttp PYSEC-2024-26 medium - 3.0.0 33ccdfb0a12690af5bb49bda2319ec0907fa7827
aiohttp PYSEC-2023-251 medium - 3.0.0 e4ae01c2077d2cfa116aa82e4ff6866857f7c466
aiohttp PYSEC-2023-251 medium - 3.0.0 e4ae01c2077d2cfa116aa82e4ff6866857f7c466
aiohttp CVE-2024-23829 medium aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators 3.0.0 -
aiohttp CVE-2023-49082 medium aiohttp's ClientSession is vulnerable to CRLF injection via method 3.0.0 -
aiohttp PYSEC-2024-26 medium - 3.0.0 33ccdfb0a12690af5bb49bda2319ec0907fa7827
aiohttp CVE-2023-37276 MODERATE aiohttp vulnerable to HTTP request smuggling 3.0.0 -
aiohttp GHSA-w2fm-2cpv-w7v5 MODERATE aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage 3.0.0 3.13.4
aiohttp GHSA-7gpw-8wmc-pm8g MODERATE aiohttp Cross-site Scripting vulnerability on index pages for static file handling 3.0.0 3.9.4
aiohttp CVE-2024-27306 MODERATE aiohttp vulnerable to XSS on index pages for static file handling 3.0.0 -
aiohttp CVE-2024-52304 MODERATE aiohttp vulnerable to request smuggling due to incorrect parsing of chunk extensions 3.0.0 -
aiohttp GHSA-8495-4g3g-x7pr MODERATE aiohttp allows request smuggling due to incorrect parsing of chunk extensions 3.0.0 3.10.11
aiohttp GHSA-8qpw-xqxj-h4r2 MODERATE aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators 3.0.0 3.9.2
aiohttp GHSA-63hw-fmq6-xxg2 MODERATE aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines 3.0.0 3.14.1
aiohttp GHSA-g84x-mcqj-x9qq MODERATE AIOHTTP vulnerable to DoS through chunked messages 3.0.0 3.13.3
aiohttp CVE-2025-69229 MODERATE AIOHTTP vulnerable to DoS through chunked messages 3.0.0 -
aiohttp GHSA-jj3x-wxrx-4x23 MODERATE AIOHTTP vulnerable to DoS when bypassing asserts 3.0.0 3.13.3
aiohttp CVE-2025-69227 MODERATE AIOHTTP vulnerable to DoS when bypassing asserts 3.0.0 -
aiohttp GHSA-4fvr-rgm6-gqmc MODERATE aiohttp: HTTP/1 Pipelined Requests Queue Without Limit 3.0.0 3.14.1
aiohttp PYSEC-2023-120 MODERATE aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser 3.0.0 3.8.5
aiohttp GHSA-xcgm-r5h9-7989 MODERATE aiohttp: Incomplete websocket frame payloads bypass memory limits 3.0.0 3.14.1
aiohttp GHSA-45c4-8wx5-qw6w MODERATE aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser 3.0.0 3.8.5
aiohttp PYSEC-2023-250 MODERATE - 3.0.0 1e86b777e61cf4eefc7d92fa57fa19dcc676013b
aiohttp GHSA-gfw2-4jvh-wgfg MODERATE AIOHTTP has problems in HTTP parser (the python one, not llhttp) 3.0.0 3.8.6
aiohttp CVE-2023-47627 MODERATE Request smuggling in aiohttp 3.0.0 -
aiohttp PYSEC-2023-246 MODERATE - 3.0.0 d5c12ba890557a575c313bb3017910d7616fce3d
aiohttp GHSA-6jhg-hg63-jvvf MODERATE AIOHTTP vulnerable to denial of service through large payloads 3.0.0 3.13.3
aiohttp CVE-2023-49081 MODERATE aiohttp's ClientSession is vulnerable to CRLF injection via version 3.0.0 -
aiohttp GHSA-qvrw-v9rv-5rjx MODERATE aiohttp's ClientSession is vulnerable to CRLF injection via method 3.0.0 3.9.0
aiohttp GHSA-q3qx-c6g2-7pw2 MODERATE aiohttp's ClientSession is vulnerable to CRLF injection via version 3.0.0 3.9.0
aiohttp GHSA-m5qp-6w8w-w647 MODERATE AIOHTTP has a Multipart Header Size Bypass 3.0.0 3.13.4
aiohttp GHSA-c427-h43c-vf67 MODERATE AIOHTTP accepts duplicate Host headers 3.0.0 3.13.4
aiohttp GHSA-hpj7-wq8m-9hgp MODERATE aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges 3.0.0 3.14.1
aiohttp CVE-2025-69228 MODERATE AIOHTTP vulnerable to denial of service through large payloads 3.0.0 -
aiohttp GHSA-pjjw-qhg8-p2p9 MODERATE aiohttp has vulnerable dependency that is vulnerable to request smuggling 3.0.0 3.8.6
aiohttp GHSA-g3cq-j2xw-wf74 MODERATE aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup 3.0.0 3.14.1
aiohttp GHSA-jg22-mg44-37j8 MODERATE AIOHTTP is Vulnerable to Deserialization of Untrusted Data 3.0.0 3.14.0
aiohttp GHSA-p998-jp59-783m MODERATE AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows 3.0.0 3.13.4
aiohttp GHSA-hg6j-4rv6-33pg MODERATE AIOHTTP is vulnerable to cross-origin redirect with per-request cookies 3.0.0 3.14.0
aiohttp GHSA-c427-h43c-vf67 MODERATE AIOHTTP accepts duplicate Host headers 3.0.0 3.13.4
aiohttp GHSA-jg22-mg44-37j8 MODERATE AIOHTTP is Vulnerable to Deserialization of Untrusted Data 3.0.0 3.14.0
aiohttp GHSA-pjjw-qhg8-p2p9 MODERATE aiohttp has vulnerable dependency that is vulnerable to request smuggling 3.0.0 3.8.6
aiohttp GHSA-hg6j-4rv6-33pg MODERATE AIOHTTP is vulnerable to cross-origin redirect with per-request cookies 3.0.0 3.14.0
aiohttp GHSA-xcgm-r5h9-7989 MODERATE aiohttp: Incomplete websocket frame payloads bypass memory limits 3.0.0 3.14.1
aiohttp GHSA-p998-jp59-783m MODERATE AIOHTTP affected by UNC SSRF/NTLMv2 Credential Theft/Local File Read in static resource handler on Windows 3.0.0 3.13.4
aiohttp GHSA-g3cq-j2xw-wf74 MODERATE aiohttp: Unread Compressed Request Bodies Bypass client_max_size During Cleanup 3.0.0 3.14.1
aiohttp GHSA-m5qp-6w8w-w647 MODERATE AIOHTTP has a Multipart Header Size Bypass 3.0.0 3.13.4
aiohttp GHSA-qvrw-v9rv-5rjx MODERATE aiohttp's ClientSession is vulnerable to CRLF injection via method 3.0.0 3.9.0
aiohttp PYSEC-2023-246 MODERATE - 3.0.0 d5c12ba890557a575c313bb3017910d7616fce3d
aiohttp GHSA-6jhg-hg63-jvvf MODERATE AIOHTTP vulnerable to denial of service through large payloads 3.0.0 3.13.3
aiohttp CVE-2025-69228 MODERATE AIOHTTP vulnerable to denial of service through large payloads 3.0.0 -
aiohttp CVE-2023-47627 MODERATE Request smuggling in aiohttp 3.0.0 -
aiohttp GHSA-gfw2-4jvh-wgfg MODERATE AIOHTTP has problems in HTTP parser (the python one, not llhttp) 3.0.0 3.8.6
aiohttp CVE-2025-69227 MODERATE AIOHTTP vulnerable to DoS when bypassing asserts 3.0.0 -
aiohttp GHSA-hpj7-wq8m-9hgp MODERATE aiohttp: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges 3.0.0 3.14.1
aiohttp GHSA-jj3x-wxrx-4x23 MODERATE AIOHTTP vulnerable to DoS when bypassing asserts 3.0.0 3.13.3
aiohttp CVE-2025-69229 MODERATE AIOHTTP vulnerable to DoS through chunked messages 3.0.0 -
aiohttp GHSA-g84x-mcqj-x9qq MODERATE AIOHTTP vulnerable to DoS through chunked messages 3.0.0 3.13.3
aiohttp GHSA-63hw-fmq6-xxg2 MODERATE aiohttp: C HTTP Parser Bypasses max_line_size for Fragmented Lines 3.0.0 3.14.1
aiohttp CVE-2024-27306 MODERATE aiohttp vulnerable to XSS on index pages for static file handling 3.0.0 -
aiohttp GHSA-q3qx-c6g2-7pw2 MODERATE aiohttp's ClientSession is vulnerable to CRLF injection via version 3.0.0 3.9.0
aiohttp CVE-2023-49081 MODERATE aiohttp's ClientSession is vulnerable to CRLF injection via version 3.0.0 -
aiohttp PYSEC-2023-250 MODERATE - 3.0.0 1e86b777e61cf4eefc7d92fa57fa19dcc676013b
aiohttp GHSA-45c4-8wx5-qw6w MODERATE aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser 3.0.0 3.8.5
aiohttp CVE-2023-37276 MODERATE aiohttp vulnerable to HTTP request smuggling 3.0.0 -
aiohttp PYSEC-2023-120 MODERATE aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser 3.0.0 3.8.5
aiohttp GHSA-7gpw-8wmc-pm8g MODERATE aiohttp Cross-site Scripting vulnerability on index pages for static file handling 3.0.0 3.9.4
aiohttp GHSA-w2fm-2cpv-w7v5 MODERATE aiohttp allows unlimited trailer headers, leading to possible uncapped memory usage 3.0.0 3.13.4
aiohttp CVE-2024-52304 MODERATE aiohttp vulnerable to request smuggling due to incorrect parsing of chunk extensions 3.0.0 -
aiohttp GHSA-4fvr-rgm6-gqmc MODERATE aiohttp: HTTP/1 Pipelined Requests Queue Without Limit 3.0.0 3.14.1
aiohttp GHSA-8495-4g3g-x7pr MODERATE aiohttp allows request smuggling due to incorrect parsing of chunk extensions 3.0.0 3.10.11
aiohttp GHSA-8qpw-xqxj-h4r2 MODERATE aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators 3.0.0 3.9.2
pydantic GHSA-mr82-8j83-vxmv MODERATE Pydantic regular expression denial of service 2 2.4.0
pydantic CVE-2024-3772 MODERATE - 2 -
pydantic CVE-2024-3772 MODERATE - 2 -
pydantic GHSA-mr82-8j83-vxmv MODERATE Pydantic regular expression denial of service 2 2.4.0
pytest CVE-2025-71176 MODERATE - 7.1.3 -
pytest GHSA-6w46-j5rx-g56g MODERATE pytest has vulnerable tmpdir handling 7.1.3 9.0.3
pytest CVE-2025-71176 MODERATE - 7.1.3 -
pytest GHSA-6w46-j5rx-g56g MODERATE pytest has vulnerable tmpdir handling 7.1.3 9.0.3
pytest CVE-2025-71176 MODERATE - 7.1.3 -
pytest GHSA-6w46-j5rx-g56g MODERATE pytest has vulnerable tmpdir handling 7.1.3 9.0.3
pytest CVE-2025-71176 MODERATE - 7.1.3 -
pytest GHSA-6w46-j5rx-g56g MODERATE pytest has vulnerable tmpdir handling 7.1.3 9.0.3
aiohttp GHSA-m6qw-4cw2-hm4m LOW aiohttp: CRLF injection in multipart headers 3.0.0 3.14.0
aiohttp GHSA-3wq7-rqq7-wx6j LOW AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS 3.0.0 3.13.4
aiohttp CVE-2023-47641 LOW Inconsistent interpretation of Content-Length vs. Transfer-Encoding in aiohttp 3.0.0 -
aiohttp CVE-2025-69225 LOW AIOHTTP Regex Mismatch Allows Unicode in ASCII-Only Protocol Fields 3.0.0 -
aiohttp GHSA-mqqc-3gqh-h2x8 LOW AIOHTTP has unicode match groups in regexes for ASCII protocol elements 3.0.0 3.13.3
aiohttp PYSEC-2023-247 LOW - 3.0.0 f016f0680e4ace6742b03a70cb0382ce86abe371
aiohttp GHSA-966j-vmvw-g2g9 LOW AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect 3.0.0 3.13.4
aiohttp GHSA-2fqr-mr3j-6wp8 LOW aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence 3.0.0 3.14.1
aiohttp GHSA-9x8q-7h8h-wcw9 LOW aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnect 3.0.0 3.14.1
aiohttp GHSA-hcc4-c3v8-rx92 LOW AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector 3.0.0 3.13.4
aiohttp GHSA-4m7w-qmgq-4wj5 LOW aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections 3.0.0 3.14.1
aiohttp GHSA-63hf-3vf5-4wqf LOW AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass 3.0.0 3.13.4
aiohttp GHSA-mwh4-6h8g-pg8w LOW AIOHTTP has HTTP response splitting via \r in reason phrase 3.0.0 3.13.4
aiohttp CVE-2025-53643 LOW AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections 3.0.0 -
aiohttp GHSA-2vrm-gr82-f7m5 LOW AIOHTTP has CRLF injection through multipart part content type header construction 3.0.0 3.13.4
aiohttp GHSA-v6wp-4m6f-gcjg LOW aiohttp Open Redirect vulnerability (normalize_path_middleware middleware) 3.0.0 3.7.4
aiohttp CVE-2021-21330 LOW - 3.0.0 -
aiohttp PYSEC-2021-76 LOW - 3.0.0 2545222a3853e31ace15d87ae0e2effb7da0c96b
aiohttp GHSA-xx9p-xxvh-7g8j LOW Aiohttp has inconsistent interpretation of Content-Length vs. Transfer-Encoding differing in C and Python fallbacks 3.0.0 3.8.0
aiohttp GHSA-fh55-r93g-j68g LOW AIOHTTP Vulnerable to Cookie Parser Warning Storm 3.0.0 3.13.3
aiohttp GHSA-9548-qrrj-x5pj LOW AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections 3.0.0 3.12.14
aiohttp CVE-2025-69226 LOW AIOHTTP allows for a brute-force leak of internal static filepath components 3.0.0 -
aiohttp CVE-2025-69230 LOW AIOHTTP Vulnerable to Cookie Parser Warning Storm 3.0.0 -
aiohttp GHSA-54jq-c3m8-4m76 LOW AIOHTTP vulnerable to brute-force leak of internal static file path components 3.0.0 3.13.3
aiohttp CVE-2025-69224 LOW AIOHTTP's Unicode processing of header values could cause parsing discrepancies 3.0.0 -
aiohttp GHSA-69f9-5gxw-wvc2 LOW AIOHTTP's unicode processing of header values could cause parsing discrepancies 3.0.0 3.13.3
aiohttp CVE-2023-47641 LOW Inconsistent interpretation of Content-Length vs. Transfer-Encoding in aiohttp 3.0.0 -
aiohttp CVE-2025-69230 LOW AIOHTTP Vulnerable to Cookie Parser Warning Storm 3.0.0 -
aiohttp PYSEC-2021-76 LOW - 3.0.0 2545222a3853e31ace15d87ae0e2effb7da0c96b
aiohttp GHSA-54jq-c3m8-4m76 LOW AIOHTTP vulnerable to brute-force leak of internal static file path components 3.0.0 3.13.3
aiohttp CVE-2025-69224 LOW AIOHTTP's Unicode processing of header values could cause parsing discrepancies 3.0.0 -
aiohttp GHSA-3wq7-rqq7-wx6j LOW AIOHTTP has late size enforcement for non-file multipart fields causes memory DoS 3.0.0 3.13.4
aiohttp GHSA-69f9-5gxw-wvc2 LOW AIOHTTP's unicode processing of header values could cause parsing discrepancies 3.0.0 3.13.3
aiohttp GHSA-9548-qrrj-x5pj LOW AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections 3.0.0 3.12.14
aiohttp CVE-2025-53643 LOW AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections 3.0.0 -
aiohttp GHSA-hcc4-c3v8-rx92 LOW AIOHTTP Affected by Denial of Service (DoS) via Unbounded DNS Cache in TCPConnector 3.0.0 3.13.4
aiohttp CVE-2021-21330 LOW - 3.0.0 -
aiohttp GHSA-4m7w-qmgq-4wj5 LOW aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections 3.0.0 3.14.1
aiohttp GHSA-m6qw-4cw2-hm4m LOW aiohttp: CRLF injection in multipart headers 3.0.0 3.14.0
aiohttp CVE-2025-69226 LOW AIOHTTP allows for a brute-force leak of internal static filepath components 3.0.0 -
aiohttp GHSA-63hf-3vf5-4wqf LOW AIOHTTP's C parser (llhttp) accepts null bytes and control characters in response header values - header injection/security bypass 3.0.0 3.13.4
aiohttp GHSA-2fqr-mr3j-6wp8 LOW aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence 3.0.0 3.14.1
aiohttp GHSA-966j-vmvw-g2g9 LOW AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect 3.0.0 3.13.4
aiohttp GHSA-fh55-r93g-j68g LOW AIOHTTP Vulnerable to Cookie Parser Warning Storm 3.0.0 3.13.3
aiohttp GHSA-v6wp-4m6f-gcjg LOW aiohttp Open Redirect vulnerability (normalize_path_middleware middleware) 3.0.0 3.7.4
aiohttp PYSEC-2023-247 LOW - 3.0.0 f016f0680e4ace6742b03a70cb0382ce86abe371
aiohttp GHSA-xx9p-xxvh-7g8j LOW Aiohttp has inconsistent interpretation of Content-Length vs. Transfer-Encoding differing in C and Python fallbacks 3.0.0 3.8.0
aiohttp GHSA-mwh4-6h8g-pg8w LOW AIOHTTP has HTTP response splitting via \r in reason phrase 3.0.0 3.13.4
aiohttp GHSA-2vrm-gr82-f7m5 LOW AIOHTTP has CRLF injection through multipart part content type header construction 3.0.0 3.13.4
aiohttp CVE-2025-69225 LOW AIOHTTP Regex Mismatch Allows Unicode in ASCII-Only Protocol Fields 3.0.0 -
aiohttp GHSA-mqqc-3gqh-h2x8 LOW AIOHTTP has unicode match groups in regexes for ASCII protocol elements 3.0.0 3.13.3
aiohttp GHSA-9x8q-7h8h-wcw9 LOW aiohttp: Payload Response Resources Are Not Closed After Mid-Body Disconnect 3.0.0 3.14.1
⚠️ Dependencies that have Reached EOL (6)
Dependency Unsafe Version EOL Date New Version Path
aiohttp 3.0.0 - 3.14.1 samples/openapi3/client/petstore/python-aiohttp/requirements.txt
aiohttp 3.0.0 - 3.14.1 samples/openapi3/client/petstore/python-pydantic-v1-aiohttp/requirements.txt
pycryptodome 3.9.0 - 3.23.0 samples/openapi3/client/petstore/python-aiohttp/requirements.txt
pycryptodome 3.9.0 - 3.23.0 samples/openapi3/client/petstore/python-pydantic-v1-aiohttp/requirements.txt
pycryptodome 3.9.0 - 3.23.0 samples/openapi3/client/petstore/python-pydantic-v1/requirements.txt
pycryptodome 3.9.0 - 3.23.0 samples/openapi3/client/petstore/python/requirements.txt

Review Checklist

Standard review:

  • Review changes for compatibility with your code
  • Check for breaking changes in release notes
  • Run tests locally or wait for CI
  • Approve and merge this PR

Update Mode: all_vulns

🤖 Generated by DataDog Automated Dependency Management System

@datadog-prod-us1-5

datadog-prod-us1-5 Bot commented Jun 16, 2026

Copy link
Copy Markdown

Pipelines

Fix all issues with BitsAI

⚠️ Warnings

🚦 17 Pipeline jobs failed

OpenAPI Generator | Samples up-to-date   View in Datadog   GitHub Actions

Python Client pydantic v1: Petstore | Test Python client (3.10, samples/openapi3/client/petstore/python-pydantic-v1-aiohttp)   View in Datadog   GitHub Actions

Python Client pydantic v1: Petstore | Test Python client (3.11, samples/openapi3/client/petstore/python-pydantic-v1-aiohttp)   View in Datadog   GitHub Actions

View all 17 failed jobs.

Useful? React with 👍 / 👎

This comment will be updated automatically if new data arrives.
🔗 Commit SHA: eb29a99 | Docs | Datadog PR Page | Give us feedback!

@gh-worker-campaigns-3e9aa4
gh-worker-campaigns-3e9aa4 Bot deleted the engraver-auto-version-upgrade/minorpatch/pip/openapi3/2-1781594209 branch August 9, 2026 14:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants