SUSE-SU-2026:4031-1
Dashboard / Vulnerabilities / SUSE-SU-2026:4031-1
SUSE-SU-2026:4031-1
Summary: Security update for python-aiohttp
Details: This update for python-aiohttp fixes the following issues: - CVE-2026-59881: excessive resource consumption due to WebSocket client accepting compressed frames without negotiated permessage-deflate (bsc#1273125). - CVE-2026-69243: HTTP request smuggling via the WebSocket upgrade procedure (bsc#1273553). - CVE-2026-69244: out-of-bounds heap read in the C response parser while building an error message for a malformed response (bsc#1273552).
References: https://www.suse.com/support/update/announcement/2026/suse-su-20264031-1/, https://bugzilla.suse.com/1273125, https://bugzilla.suse.com/1273552, https://bugzilla.suse.com/1273553, https://www.suse.com/security/cve/CVE-2026-59881, https://www.suse.com/security/cve/CVE-2026-69243, https://www.suse.com/security/cve/CVE-2026-69244
Affected packages
Package
Name: python-aiohttp
Purl: pkg:rpm/suse/python-aiohttp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP4
Affected ranges
Type: ECOSYSTEM
Events:
