[oe][meta-python][wrynose][PATCH 02/10] python3-aiohttp: fix CVE-2026-47265

"Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" <[email protected]>
Newsgroups org.openembedded.lists.openembedded-devel
Message-ID <[email protected]>
From: Darsh Kelaiya <[email protected]>

This patch applies the upstream fix as referenced in [2], using
the commit shown in [1].

[1] https://github.com/aio-libs/aiohttp/commit/f54c40851b0d6c4bbdab97ba518a223adda32478
[2] https://github.com/advisories/GHSA-hg6j-4rv6-33pg

Signed-off-by: Darsh Kelaiya <[email protected]>
---
 .../python3-aiohttp/CVE-2026-47265.patch      | 64 +++++++++++++++++++
 .../python/python3-aiohttp_3.13.5.bb          |  1 +
 2 files changed, 65 insertions(+)
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-47265.patch

diff --git a/meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-47265.patch b/meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-47265.patch
new file mode 100644
index 0000000000..98e866866b
--- /dev/null
+++ b/meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-47265.patch
@@ -0,0 +1,64 @@
+From 54aaf333cfe59f62d01ed06c8951da268ab2fb18 Mon Sep 17 00:00:00 2001
+From: Sam Bull <[email protected]>
+Date: Tue, 19 May 2026 01:23:00 +0100
+Subject: [PATCH] Drop cookies on redirect (#12550) (#12640)
+
+CVE: CVE-2026-47265
+Upstream-Status: Backport [https://github.com/aio-libs/aiohttp/commit/f54c40851b0d6c4bbdab97ba518a223adda32478]
+
+(cherry picked from commit d57efb05f5073071ceb2d3b35d72d9d0bc4512a2)
+(cherry picked from commit f54c40851b0d6c4bbdab97ba518a223adda32478)
+Signed-off-by: Darsh Kelaiya <[email protected]>
+---
+ CHANGES/12540.bugfix.rst        |  1 +
+ aiohttp/client.py               |  1 +
+ tests/test_client_functional.py | 16 ++++++++++++++--
+ 3 files changed, 16 insertions(+), 2 deletions(-)
+ create mode 100644 CHANGES/12540.bugfix.rst
+
+diff --git a/CHANGES/12540.bugfix.rst b/CHANGES/12540.bugfix.rst
+new file mode 100644
+index 000000000..dfd98129e
+--- /dev/null
++++ b/CHANGES/12540.bugfix.rst
+@@ -0,0 +1 @@
++Fixed per-request ``cookies`` not being dropped on cross-origin redirects -- by :user:`Dreamsorcerer`.
+diff --git a/aiohttp/client.py b/aiohttp/client.py
+index 5d10d3e43..0637eff6b 100644
+--- a/aiohttp/client.py
++++ b/aiohttp/client.py
+@@ -892,6 +892,7 @@ class ClientSession:
+ 
+                         if url.origin() != redirect_origin:
+                             auth = None
++                            cookies = None
+                             headers.pop(hdrs.AUTHORIZATION, None)
+                             headers.pop(hdrs.COOKIE, None)
+                             headers.pop(hdrs.PROXY_AUTHORIZATION, None)
+diff --git a/tests/test_client_functional.py b/tests/test_client_functional.py
+index 118ce19ca..ea31567c4 100644
+--- a/tests/test_client_functional.py
++++ b/tests/test_client_functional.py
+@@ -3564,8 +3564,20 @@ async def test_auth_persist_on_redirect_to_other_host_with_global_auth(
+     async with aiohttp.ClientSession(
+         connector=connector, auth=aiohttp.BasicAuth("user", "pass")
+     ) as client:
+-        resp = await client.get(url_from)
+-        assert resp.status == 200
++        async with client.get(
++            url_from,
++            headers={
++                "Proxy-Authorization": "Basic dXNlcjpwYXNz",
++                "Cookie": "a=b",
++            },
++        ) as resp:
++            assert resp.status == 200
++        async with client.get(
++            url_from,
++            headers={"Proxy-Authorization": "Basic dXNlcjpwYXNz"},
++            cookies={"a": "b"},
++        ) as resp:
++            assert resp.status == 200
+ 
+ 
+ async def test_drop_auth_on_redirect_to_other_host_with_global_auth_and_base_url(
diff --git a/meta-python/recipes-devtools/python/python3-aiohttp_3.13.5.bb b/meta-python/recipes-devtools/python/python3-aiohttp_3.13.5.bb
index bce27905aa..d17043bc3e 100644
--- a/meta-python/recipes-devtools/python/python3-aiohttp_3.13.5.bb
+++ b/meta-python/recipes-devtools/python/python3-aiohttp_3.13.5.bb
@@ -8,6 +8,7 @@ SRC_URI[sha256sum] = "9d98cc980ecc96be6eb4c1994ce35d28d8b1f5e5208a23b421187d1209
 
 SRC_URI += " \
     file://CVE-2026-34993.patch \
+    file://CVE-2026-47265.patch \
 "
 
 CVE_PRODUCT = "aiohttp"
-- 
2.35.6
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.