[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-SUSE-SU-2026:3207-1":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T17:35:29.592Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":52,"duplicates":53,"related":54,"reserved_at":9,"published_at":74,"modified_at":75,"state":9,"summary":76,"references_raw":78,"kevs":239,"epss":9,"epss_history":240,"metrics":241,"affected":242},"SUSE-SU-2026:3207-1","Security update for python-aiohttp\n\nThis update for python-aiohttp fixes the following issues\n\n- CVE-2026-22815: insufficient restrictions in header/trailer handling can cause uncapped memory usage and a denial of\n  service (bsc#1261320).\n- CVE-2026-34513: unbounded DNS cache can cause a excessive memory usage and lead to a denial of service (bsc#1261321).\n- CVE-2026-34514: `content_type` parameter manipulation can lead to header injection (bsc#1261322).\n- CVE-2026-34516: response with excessive multipart headers can use more memory than intended and cause a denial of\n  service (bsc#1261329).\n- CVE-2026-34517: large multipart form fields read into memory without size check can cause a denial of service\n  (bsc#1261331).\n- CVE-2026-34518: retained `Cookie` and `Proxy-Authorization` headers when following redirects can lead to information\n  disclosure (bsc#1261332).\n- CVE-2026-34519: response `reason` parameter can be use to perform header injection (bsc#1261334).\n- CVE-2026-34520: improper character handling by C parser can lead to header injection (bsc#1261335).\n- CVE-2026-34525: multiple `Host` headers allow for potential security bypass in proxy servers (bsc#1261343).\n- CVE-2026-34993: loading untrusted input in `CookieJar.load()` can lead to arbitrary code execution (bsc#1267471).\n- CVE-2026-47265: cookies set with the `cookies` parameter on requests are sent after following a cross-origin redirect\n  and can leak sensitive data (bsc#1267561).\n- CVE-2026-50269: improper validation of user-controlled strings allows for CRLF injection in multipart headers\n  (bsc#1268398).\n- CVE-2026-54273: no limit in the HTTP/1 pipelined request queue can lead to excessive resource consumption\n  (bsc#1268543).\n- CVE-2026-54274: incomplete websocket frame payloads can bypass memory use limits and cause a DoS via excessive\n  resource consumption (bsc#1268544).\n- CVE-2026-54275: `server_hostname` TLS SNI check bypass when an existing connection is reused (bsc#1268549).\n- CVE-2026-54277: `max_line_size` bypass when using the optimised C HTTP parser can lead to excessive resource\n  consumption (bsc#1268556).\n- CVE-2026-54278: unread compressed request bodies can bypass `client_max_size` during cleanup and cause a DoS\n  (bsc#1268559).\n- CVE-2026-54279: host-only cookies become domain cookies after `CookieJar` persistence (bsc#1268560).\n- CVE-2026-54280: payload resources are not closed correctly when a client disconnects in the middle of a write and\n  can cause resource starvation (bsc#1268561).\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34,36,38,40,42,44,46,48,50],{"_key":15},"CVE-2026-22815",{"_key":17},"CVE-2026-34513",{"_key":19},"CVE-2026-34514",{"_key":21},"CVE-2026-34516",{"_key":23},"CVE-2026-34517",{"_key":25},"CVE-2026-34518",{"_key":27},"CVE-2026-34519",{"_key":29},"CVE-2026-34520",{"_key":31},"CVE-2026-34525",{"_key":33},"CVE-2026-34993",{"_key":35},"CVE-2026-47265",{"_key":37},"CVE-2026-50269",{"_key":39},"CVE-2026-54273",{"_key":41},"CVE-2026-54274",{"_key":43},"CVE-2026-54275",{"_key":45},"CVE-2026-54277",{"_key":47},"CVE-2026-54278",{"_key":49},"CVE-2026-54279",{"_key":51},"CVE-2026-54280",[],[],[55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},{"_key":39},{"_key":41},{"_key":43},{"_key":45},{"_key":47},{"_key":49},{"_key":51},"2026-07-23T14:10:50Z","2026-07-24T17:16:06.381467415Z",{"cisa_kev":77,"cisa_ransomware":77,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[79,85,90,94,98,102,106,110,114,118,122,126,130,134,138,142,146,150,154,158,162,167,171,175,179,183,187,191,195,199,203,207,211,215,219,223,227,231,235],{"url":80,"sources":81,"tags":83},"https://www.suse.com/support/update/announcement/2026/suse-su-20263207-1/",[82],"osv_suse",[84],"Advisory",{"url":86,"sources":87,"tags":88},"https://bugzilla.suse.com/1261320",[82],[89],"REPORT",{"url":91,"sources":92,"tags":93},"https://bugzilla.suse.com/1261321",[82],[89],{"url":95,"sources":96,"tags":97},"https://bugzilla.suse.com/1261322",[82],[89],{"url":99,"sources":100,"tags":101},"https://bugzilla.suse.com/1261329",[82],[89],{"url":103,"sources":104,"tags":105},"https://bugzilla.suse.com/1261331",[82],[89],{"url":107,"sources":108,"tags":109},"https://bugzilla.suse.com/1261332",[82],[89],{"url":111,"sources":112,"tags":113},"https://bugzilla.suse.com/1261334",[82],[89],{"url":115,"sources":116,"tags":117},"https://bugzilla.suse.com/1261335",[82],[89],{"url":119,"sources":120,"tags":121},"https://bugzilla.suse.com/1261343",[82],[89],{"url":123,"sources":124,"tags":125},"https://bugzilla.suse.com/1267471",[82],[89],{"url":127,"sources":128,"tags":129},"https://bugzilla.suse.com/1267561",[82],[89],{"url":131,"sources":132,"tags":133},"https://bugzilla.suse.com/1268398",[82],[89],{"url":135,"sources":136,"tags":137},"https://bugzilla.suse.com/1268543",[82],[89],{"url":139,"sources":140,"tags":141},"https://bugzilla.suse.com/1268544",[82],[89],{"url":143,"sources":144,"tags":145},"https://bugzilla.suse.com/1268549",[82],[89],{"url":147,"sources":148,"tags":149},"https://bugzilla.suse.com/1268556",[82],[89],{"url":151,"sources":152,"tags":153},"https://bugzilla.suse.com/1268559",[82],[89],{"url":155,"sources":156,"tags":157},"https://bugzilla.suse.com/1268560",[82],[89],{"url":159,"sources":160,"tags":161},"https://bugzilla.suse.com/1268561",[82],[89],{"url":163,"sources":164,"tags":165},"https://www.suse.com/security/cve/CVE-2026-22815",[82],[166],"WEB",{"url":168,"sources":169,"tags":170},"https://www.suse.com/security/cve/CVE-2026-34513",[82],[166],{"url":172,"sources":173,"tags":174},"https://www.suse.com/security/cve/CVE-2026-34514",[82],[166],{"url":176,"sources":177,"tags":178},"https://www.suse.com/security/cve/CVE-2026-34516",[82],[166],{"url":180,"sources":181,"tags":182},"https://www.suse.com/security/cve/CVE-2026-34517",[82],[166],{"url":184,"sources":185,"tags":186},"https://www.suse.com/security/cve/CVE-2026-34518",[82],[166],{"url":188,"sources":189,"tags":190},"https://www.suse.com/security/cve/CVE-2026-34519",[82],[166],{"url":192,"sources":193,"tags":194},"https://www.suse.com/security/cve/CVE-2026-34520",[82],[166],{"url":196,"sources":197,"tags":198},"https://www.suse.com/security/cve/CVE-2026-34525",[82],[166],{"url":200,"sources":201,"tags":202},"https://www.suse.com/security/cve/CVE-2026-34993",[82],[166],{"url":204,"sources":205,"tags":206},"https://www.suse.com/security/cve/CVE-2026-47265",[82],[166],{"url":208,"sources":209,"tags":210},"https://www.suse.com/security/cve/CVE-2026-50269",[82],[166],{"url":212,"sources":213,"tags":214},"https://www.suse.com/security/cve/CVE-2026-54273",[82],[166],{"url":216,"sources":217,"tags":218},"https://www.suse.com/security/cve/CVE-2026-54274",[82],[166],{"url":220,"sources":221,"tags":222},"https://www.suse.com/security/cve/CVE-2026-54275",[82],[166],{"url":224,"sources":225,"tags":226},"https://www.suse.com/security/cve/CVE-2026-54277",[82],[166],{"url":228,"sources":229,"tags":230},"https://www.suse.com/security/cve/CVE-2026-54278",[82],[166],{"url":232,"sources":233,"tags":234},"https://www.suse.com/security/cve/CVE-2026-54279",[82],[166],{"url":236,"sources":237,"tags":238},"https://www.suse.com/security/cve/CVE-2026-54280",[82],[166],[],[],[],[243,256,260,264,268,272,276,280,284,288,292,296],{"ecosystem":244,"name":245,"vendor":246,"product":247,"cpe_part":9,"purl_type":248,"purl_namespace":246,"purl_name":247,"source":9,"versions":249},"SUSE Linux Enterprise","python-aiohttp","suse","python-aiohttp&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS","rpm",[250],{"version":251,"is_range":252,"range_type":253,"version_start":9,"version_start_type":9,"version_end":254,"version_end_type":255,"fixed_in":9},"lt3_9_3_150400_10_43_1",true,"ecosystem","3.9.3-150400.10.43.1","excluding",{"ecosystem":244,"name":245,"vendor":246,"product":257,"cpe_part":9,"purl_type":248,"purl_namespace":246,"purl_name":257,"source":9,"versions":258},"python-aiohttp&distro=SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS",[259],{"version":251,"is_range":252,"range_type":253,"version_start":9,"version_start_type":9,"version_end":254,"version_end_type":255,"fixed_in":9},{"ecosystem":244,"name":245,"vendor":246,"product":261,"cpe_part":9,"purl_type":248,"purl_namespace":246,"purl_name":261,"source":9,"versions":262},"python-aiohttp&distro=SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS",[263],{"version":251,"is_range":252,"range_type":253,"version_start":9,"version_start_type":9,"version_end":254,"version_end_type":255,"fixed_in":9},{"ecosystem":244,"name":245,"vendor":246,"product":265,"cpe_part":9,"purl_type":248,"purl_namespace":246,"purl_name":265,"source":9,"versions":266},"python-aiohttp&distro=SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS",[267],{"version":251,"is_range":252,"range_type":253,"version_start":9,"version_start_type":9,"version_end":254,"version_end_type":255,"fixed_in":9},{"ecosystem":244,"name":245,"vendor":246,"product":269,"cpe_part":9,"purl_type":248,"purl_namespace":246,"purl_name":269,"source":9,"versions":270},"python-aiohttp&distro=SUSE Linux Enterprise Module for Public Cloud 15 SP4",[271],{"version":251,"is_range":252,"range_type":253,"version_start":9,"version_start_type":9,"version_end":254,"version_end_type":255,"fixed_in":9},{"ecosystem":244,"name":245,"vendor":246,"product":273,"cpe_part":9,"purl_type":248,"purl_namespace":246,"purl_name":273,"source":9,"versions":274},"python-aiohttp&distro=SUSE Linux Enterprise Module for Python 3 15 SP7",[275],{"version":251,"is_range":252,"range_type":253,"version_start":9,"version_start_type":9,"version_end":254,"version_end_type":255,"fixed_in":9},{"ecosystem":244,"name":245,"vendor":246,"product":277,"cpe_part":9,"purl_type":248,"purl_namespace":246,"purl_name":277,"source":9,"versions":278},"python-aiohttp&distro=SUSE Linux Enterprise Server 15 SP4-LTSS",[279],{"version":251,"is_range":252,"range_type":253,"version_start":9,"version_start_type":9,"version_end":254,"version_end_type":255,"fixed_in":9},{"ecosystem":244,"name":245,"vendor":246,"product":281,"cpe_part":9,"purl_type":248,"purl_namespace":246,"purl_name":281,"source":9,"versions":282},"python-aiohttp&distro=SUSE Linux Enterprise Server 15 SP5-LTSS",[283],{"version":251,"is_range":252,"range_type":253,"version_start":9,"version_start_type":9,"version_end":254,"version_end_type":255,"fixed_in":9},{"ecosystem":244,"name":245,"vendor":246,"product":285,"cpe_part":9,"purl_type":248,"purl_namespace":246,"purl_name":285,"source":9,"versions":286},"python-aiohttp&distro=SUSE Linux Enterprise Server 15 SP6-LTSS",[287],{"version":251,"is_range":252,"range_type":253,"version_start":9,"version_start_type":9,"version_end":254,"version_end_type":255,"fixed_in":9},{"ecosystem":244,"name":245,"vendor":246,"product":289,"cpe_part":9,"purl_type":248,"purl_namespace":246,"purl_name":289,"source":9,"versions":290},"python-aiohttp&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP4",[291],{"version":251,"is_range":252,"range_type":253,"version_start":9,"version_start_type":9,"version_end":254,"version_end_type":255,"fixed_in":9},{"ecosystem":244,"name":245,"vendor":246,"product":293,"cpe_part":9,"purl_type":248,"purl_namespace":246,"purl_name":293,"source":9,"versions":294},"python-aiohttp&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP5",[295],{"version":251,"is_range":252,"range_type":253,"version_start":9,"version_start_type":9,"version_end":254,"version_end_type":255,"fixed_in":9},{"ecosystem":244,"name":245,"vendor":246,"product":297,"cpe_part":9,"purl_type":248,"purl_namespace":246,"purl_name":297,"source":9,"versions":298},"python-aiohttp&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP6",[299],{"version":251,"is_range":252,"range_type":253,"version_start":9,"version_start_type":9,"version_end":254,"version_end_type":255,"fixed_in":9}]