← All tasks
pythontwilio/twilio-python #780Not a task: already works

aiohttp version has multiple CVE's

envgap__twilio__twilio-python-780

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
4ed7fec29a5baccef722286033361b7092180e3c
Manifest
requirements.txt
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

twilio/twilio-python #780 · read the original issue
### Issue Summary

the aiohttp version currently used (3.8.4) has multiple security vulnerabilities with open CVE's:

- https://nvd.nist.gov/vuln/detail/CVE-2024-23334

- https://nvd.nist.gov/vuln/detail/CVE-2024-23829

- https://nvd.nist.gov/vuln/detail/CVE-2023-49082

- https://nvd.nist.gov/vuln/detail/CVE-2024-23334



aiohttp needs to be upgraded to at least 3.9.2 to resolve the issue.



### Steps to Reproduce



### Code Snippet

https://github.com/twilio/twilio-python/blob/main/setup.py#L26



### Exception/Log



### Technical details:

* twilio-python version:  9.0.2

* python version: 3.7



Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]