Bug#1143148: trixie-pu: package python-aiohttp/3.11.16-1+deb13u2

Salvatore Bonaccorso <[email protected]> Sun, 2 Aug 2026 19:06:31 +0200
Newsgroups gmane.linux.debian.devel.release
Message-ID <am95F0GetMOQ5X7H__18813.8573475712$1785690566$gmane$org@eldamar.lan>
On Fri, Jul 31, 2026 at 04:16:48AM +0200, Daniel Leidert wrote:
> Package: release.debian.org
> Severity: normal
> Tags: trixie
> X-Debbugs-Cc: [email protected]
> Control: affects -1 + src:python-aiohttp
> User: [email protected]
> Usertags: pu
> 
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA512
> 
> [ Reason ]
> 
> This update adresses a list of CVEs which should either be fixed via DSA or via
> SPU. These are the CVEs fixed:
> 
>   * CVE-2025-53643
>   * CVE-2026-22815
>   * CVE-2026-34513
>   * CVE-2026-34514
>   * CVE-2026-34516
>   * CVE-2026-34517
>   * CVE-2026-34518
>   * CVE-2026-34519
>   * CVE-2026-34520
>   * CVE-2026-34525
>   * CVE-2026-34993
>   * CVE-2026-47265
>   * CVE-2026-50269
>   * CVE-2026-54274
>   * CVE-2026-54275
>   * CVE-2026-54277
>   * CVE-2026-54279
>   * CVE-2026-54280

They are marked already no-dsa, thus the trixie-pu route is good. Can
you please add as well the fix for CVE-2026-59881 in the same batch,
this is as well no-dsa (should first be fixed as well in unstable).

Regards,
Salvatore