meta-openembedded/meta-python
Jiaying Song 59d381adca python3-aiohttp: fix CVE-2025-53643
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and
Python. Prior to version 3.12.14, the Python parser is vulnerable to a
request smuggling vulnerability due to not parsing trailer sections of
an HTTP request. If a pure Python version of aiohttp is installed (i.e.
without the usual C extensions) or AIOHTTP_NO_EXTENSIONS is enabled,
then an attacker may be able to execute a request smuggling attack to
bypass certain firewalls or proxy protections. Version 3.12.14 contains
a patch for this issue.

References:
https://nvd.nist.gov/vuln/detail/CVE-2025-53643

Signed-off-by: Jiaying Song <jiaying.song.cn@windriver.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
2025-07-27 14:35:10 -04:00
..
classes
conf python3-objgraph: Add recipe 2025-04-08 11:46:18 -07:00
licenses python3-crc32c: Declare Zlib license 2025-02-03 20:16:25 -08:00
recipes/devtool python3-breathe: Inherit ptest-python-pytest instead of ptest 2025-04-02 09:27:44 -07:00
recipes-connectivity Use https:// in HOMEPAGE variable instead of http:// 2025-03-25 18:32:07 -07:00
recipes-core pydantic: Mark host incompatible on RISCV32 2025-04-06 18:46:25 -07:00
recipes-devtools python3-aiohttp: fix CVE-2025-53643 2025-07-27 14:35:10 -04:00
recipes-extended python3-pykickstart: Upgrade 3.48 -> 3.62 2025-04-10 08:31:03 -07:00
recipes-networking/python Use https:// in HOMEPAGE variable instead of http:// 2025-03-25 18:32:07 -07:00
COPYING.MIT
README.md meta-openemnedded: Add myself as walnascar maintainer 2025-04-16 18:20:05 -07:00
SECURITY.md meta: Add SECURITY.md file to all layers 2024-11-23 09:00:14 -08:00

meta-python

Introduction

This layer is intended to be the home of python modules for OpenEmbedded.

Dependencies

The meta-python layer depends on:

URI: git://git.openembedded.org/openembedded-core
layers: meta
branch: walnascar

URI: git://git.openembedded.org/meta-openembedded
layers: meta-oe
branch: walnascar

Contributing

The meta-openembedded mailinglist (openembedded-devel@lists.openembedded.org) is used for questions, comments and patch review. It is subscriber only, so please register before posting.

Send pull requests to openembedded-devel@lists.openembedded.org with '[meta-python][walnascar]' in the subject.

When sending single patches, please use something like: git send-email -M -1 --to=openembedded-devel@lists.openembedded.org --subject-prefix='meta-python][walnascar][PATCH'

Maintenance

Layer maintainers: Armin Kuster akuster808@gmail.com