diff mbox series

[meta-python,scarthgap,06/13] python3-aiohttp: fix CVE-2026-47265

Message ID 20260928174323.1810308-7-dkelaiya@cisco.com
State New
Headers show
Series python3-aiohttp: fix multiple CVEs | expand

Commit Message

From: Darsh Kelaiya <dkelaiya@cisco.com>

This patch applies the upstream stable-branch fix in [1], which
backports the original upstream commit in [2]. The advisory
identifying the vulnerability is referenced in [3].

[1] https://github.com/aio-libs/aiohttp/commit/f54c40851b0d6c4bbdab97ba518a223adda32478
[2] https://github.com/aio-libs/aiohttp/commit/d57efb05f5073071ceb2d3b35d72d9d0bc4512a2
[3] https://nvd.nist.gov/vuln/detail/CVE-2026-47265

Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
---
 .../python3-aiohttp/CVE-2026-47265.patch      | 61 +++++++++++++++++++
 .../python/python3-aiohttp_3.9.5.bb           |  1 +
 2 files changed, 62 insertions(+)
 create mode 100644 meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-47265.patch
diff mbox series

Patch

diff --git a/meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-47265.patch b/meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-47265.patch
new file mode 100644
index 0000000000..94250c6fc4
--- /dev/null
+++ b/meta-python/recipes-devtools/python/python3-aiohttp/CVE-2026-47265.patch
@@ -0,0 +1,61 @@ 
+From b71a4e896630f25248223d05e995eab16e953a72 Mon Sep 17 00:00:00 2001
+From: Sam Bull <git@sambull.org>
+Date: Tue, 19 May 2026 01:23:00 +0100
+Subject: [PATCH] Drop cookies on redirect (#12550) (#12640)
+
+CVE: CVE-2026-47265
+Upstream-Status: Backport [https://github.com/aio-libs/aiohttp/commit/f54c40851b0d6c4bbdab97ba518a223adda32478]
+
+Backport Changes:
+- Scarthgap 3.9.5 lacks the upstream global-auth redirect test.
+- Added the per-request cookies case to the existing redirect test.
+
+(cherry picked from commit d57efb05f5073071ceb2d3b35d72d9d0bc4512a2)
+(cherry picked from commit f54c40851b0d6c4bbdab97ba518a223adda32478)
+Signed-off-by: Darsh Kelaiya <dkelaiya@cisco.com>
+---
+ CHANGES/12540.bugfix.rst        | 1 +
+ aiohttp/client.py               | 1 +
+ tests/test_client_functional.py | 6 ++++++
+ 3 files changed, 8 insertions(+)
+ create mode 100644 CHANGES/12540.bugfix.rst
+
+diff --git a/CHANGES/12540.bugfix.rst b/CHANGES/12540.bugfix.rst
+new file mode 100644
+index 000000000..dfd98129e
+--- /dev/null
++++ b/CHANGES/12540.bugfix.rst
+@@ -0,0 +1 @@
++Fixed per-request ``cookies`` not being dropped on cross-origin redirects -- by :user:`Dreamsorcerer`.
+diff --git a/aiohttp/client.py b/aiohttp/client.py
+index 0b87d7eec..87b697f85 100644
+--- a/aiohttp/client.py
++++ b/aiohttp/client.py
+@@ -683,6 +683,7 @@ class ClientSession:
+ 
+                         if url.origin() != parsed_url.origin():
+                             auth = None
++                            cookies = None
+                             headers.pop(hdrs.AUTHORIZATION, None)
+                             headers.pop(hdrs.COOKIE, None)
+                             headers.pop(hdrs.PROXY_AUTHORIZATION, None)
+diff --git a/tests/test_client_functional.py b/tests/test_client_functional.py
+index 3ca1716ba..2c531d7d3 100644
+--- a/tests/test_client_functional.py
++++ b/tests/test_client_functional.py
+@@ -2660,6 +2660,12 @@ async def test_drop_auth_on_redirect_to_other_host(
+             },
+         )
+         assert resp.status == 200
++        resp = await client.get(
++            url_from,
++            headers={"Proxy-Authorization": "Basic dXNlcjpwYXNz"},
++            cookies={"a": "b"},
++        )
++        assert resp.status == 200
+ 
+ 
+ async def test_async_with_session() -> None:
+-- 
+2.35.6
+
diff --git a/meta-python/recipes-devtools/python/python3-aiohttp_3.9.5.bb b/meta-python/recipes-devtools/python/python3-aiohttp_3.9.5.bb
index 921dc01dc3..afb8cbff7d 100644
--- a/meta-python/recipes-devtools/python/python3-aiohttp_3.9.5.bb
+++ b/meta-python/recipes-devtools/python/python3-aiohttp_3.9.5.bb
@@ -27,6 +27,7 @@  SRC_URI += "file://CVE-2024-52304.patch \
            file://CVE-2026-34520.patch \
            file://CVE-2026-34525_p1.patch \
            file://CVE-2026-34525_p2.patch \
+           file://CVE-2026-47265.patch \
            "
 
 CVE_STATUS[CVE-2026-34515] = "not-applicable-platform: Vulnerability only affects applications running on Windows"