[oe][meta-python][wrynose][PATCH 03/10] python3-aiohttp: fix CVE-2026-50269
"Darsh Kelaiya -X (dkelaiya - E INFOCHIPS PRIVATE LIMITED at Cisco)" <[email protected]>
| Newsgroups | org.openembedded.lists.openembedded-devel |
|---|---|
| Message-ID | <[email protected]> |
From: Darsh Kelaiya <[email protected]> This patch applies the upstream fix as referenced in [2], using the commit shown in [1]. [1] https://github.com/aio-libs/aiohttp/commit/bf88077ebb14f4c29924b8e8904cba20c55c28b8 [2] https://github.com/advisories/GHSA-m6qw-4cw2-hm4m Signed-off-by: Darsh Kelaiya <[email protected]> --- .../python3-aiohttp/CVE-2026-50269.patch | 81 +++++++++++++++++++ .../python/python3-aiohttp_3.13.5.bb | 1 + 2 files changed, 82 insertions(+) create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-50269.patch diff --git a/meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-50269.patch b/meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-50269.patch new file mode 100644 index 0000000000..1bde87e4e8 --- /dev/null +++ b/meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-50269.patch @@ -0,0 +1,81 @@ +From 7fb9ddce2c1a376ef46f9ec2195e5d75db60c227 Mon Sep 17 00:00:00 2001 +From: "patchback[bot]" <45432694+patchback[bot]@users.noreply.github.com> +Date: Thu, 28 May 2026 23:57:41 +0100 +Subject: [PATCH] [PR #12719/879d48d1 backport][3.14] Reject invalid bytes in + multipart/payload headers (#12720) + +**This is a backport of PR #12719 as merged into master +(879d48d1619b9bc3662037afcb8bfa790a205e9b).** + +CVE: CVE-2026-50269 +Upstream-Status: Backport [https://github.com/aio-libs/aiohttp/commit/bf88077ebb14f4c29924b8e8904cba20c55c28b8] + +Co-authored-by: Sam Bull <[email protected]> +(cherry picked from commit bf88077ebb14f4c29924b8e8904cba20c55c28b8) +Signed-off-by: Darsh Kelaiya <[email protected]> +--- + CHANGES/12706.bugfix.rst | 1 + + aiohttp/payload.py | 8 +++++--- + tests/test_payload.py | 15 +++++++++++++++ + 3 files changed, 21 insertions(+), 3 deletions(-) + create mode 100644 CHANGES/12706.bugfix.rst + +diff --git a/CHANGES/12706.bugfix.rst b/CHANGES/12706.bugfix.rst +new file mode 100644 +index 000000000..9248585f9 +--- /dev/null ++++ b/CHANGES/12706.bugfix.rst +@@ -0,0 +1 @@ ++Fixed invalid bytes being allowed in multipart/payload headers -- by :user:`Dreamsorcerer`. +diff --git a/aiohttp/payload.py b/aiohttp/payload.py +index 5b88fa094..23d127056 100644 +--- a/aiohttp/payload.py ++++ b/aiohttp/payload.py +@@ -35,6 +35,7 @@ from .helpers import ( + parse_mimetype, + sentinel, + ) ++from .http_writer import _safe_header + from .streams import StreamReader + from .typedefs import JSONEncoder, _CIMultiDict + +@@ -209,9 +210,10 @@ class Payload(ABC): + @property + def _binary_headers(self) -> bytes: + return ( +- "".join([k + ": " + v + "\r\n" for k, v in self.headers.items()]).encode( +- "utf-8" +- ) ++ "".join( ++ _safe_header(k) + ": " + _safe_header(v) + "\r\n" ++ for k, v in self.headers.items() ++ ).encode("utf-8") + + b"\r\n" + ) + +diff --git a/tests/test_payload.py b/tests/test_payload.py +index 9aa97b20d..b60aa7e7c 100644 +--- a/tests/test_payload.py ++++ b/tests/test_payload.py +@@ -101,6 +101,21 @@ def test_payload_content_type() -> None: + assert p.content_type == "application/json" + + [email protected]("bad_byte", ("\r", "\n", "\x00")) ++def test_binary_headers_reject_injection_in_value(bad_byte: str) -> None: ++ p = Payload("test", headers={"X-Custom": f"value{bad_byte}Injected: bad"}) ++ with pytest.raises(ValueError, match="header injection"): ++ p._binary_headers ++ ++ [email protected]("bad_byte", ("\r", "\n", "\x00")) ++def test_binary_headers_reject_injection_in_name(bad_byte: str) -> None: ++ p = Payload("test") ++ p.headers[f"X-Custom{bad_byte}Injected"] = "value" ++ with pytest.raises(ValueError, match="header injection"): ++ p._binary_headers ++ ++ + def test_bytes_payload_default_content_type() -> None: + p = payload.BytesPayload(b"data") + assert p.content_type == "application/octet-stream" diff --git a/meta-python/recipes-devtools/python/python3-aiohttp_3.13.5.bb b/meta-python/recipes-devtools/python/python3-aiohttp_3.13.5.bb index d17043bc3e..33ef64a59b 100644 --- a/meta-python/recipes-devtools/python/python3-aiohttp_3.13.5.bb +++ b/meta-python/recipes-devtools/python/python3-aiohttp_3.13.5.bb @@ -9,6 +9,7 @@ SRC_URI[sha256sum] = "9d98cc980ecc96be6eb4c1994ce35d28d8b1f5e5208a23b421187d1209 SRC_URI += " \ file://CVE-2026-34993.patch \ file://CVE-2026-47265.patch \ + file://CVE-2026-50269.patch \ " CVE_PRODUCT = "aiohttp" -- 2.35.6