Skip to content

Bump aiohttp to 3.13.5 in lockfile (CVE-2026-22815)#630

Merged
jhamon merged 1 commit intomainfrom
jhamon/bump-aiohttp-3.13.5
Apr 1, 2026
Merged

Bump aiohttp to 3.13.5 in lockfile (CVE-2026-22815)#630
jhamon merged 1 commit intomainfrom
jhamon/bump-aiohttp-3.13.5

Conversation

@jhamon
Copy link
Copy Markdown
Collaborator

@jhamon jhamon commented Apr 1, 2026

Summary

  • Bumps aiohttp from 3.13.3 to 3.13.5 in uv.lock
  • Fixes Dependabot alert #65: aiohttp <= 3.13.3 allows unlimited trailer headers, leading to possible uncapped memory usage (medium severity)

Test plan

  • CI passes — this is a lockfile-only change with no code modifications

Note

Low Risk
Lockfile-only dependency bump; runtime behavior changes are limited to aiohttp patch updates, with low risk aside from potential upstream regressions.

Overview
Updates the uv.lock pinned aiohttp version from 3.13.3 to 3.13.5, refreshing the associated sdist/wheel hashes and artifacts.

No application code changes; this is a dependency lock update intended to pick up the patched aiohttp release (CVE-related).

Written by Cursor Bugbot for commit 9b6efce. This will update automatically on new commits. Configure here.

Fixes Dependabot alert #65: aiohttp <= 3.13.3 allows unlimited trailer
headers, leading to possible uncapped memory usage.
@jhamon jhamon merged commit 8e506bb into main Apr 1, 2026
41 of 42 checks passed
@jhamon jhamon deleted the jhamon/bump-aiohttp-3.13.5 branch April 1, 2026 20:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant