aiohttp version has multiple CVE's
envgap__twilio__twilio-python-780
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
4ed7fec29a5baccef722286033361b7092180e3c- Manifest
requirements.txt- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
twilio/twilio-python #780 · read the original issue
### Issue Summary the aiohttp version currently used (3.8.4) has multiple security vulnerabilities with open CVE's: - https://nvd.nist.gov/vuln/detail/CVE-2024-23334 - https://nvd.nist.gov/vuln/detail/CVE-2024-23829 - https://nvd.nist.gov/vuln/detail/CVE-2023-49082 - https://nvd.nist.gov/vuln/detail/CVE-2024-23334 aiohttp needs to be upgraded to at least 3.9.2 to resolve the issue. ### Steps to Reproduce ### Code Snippet https://github.com/twilio/twilio-python/blob/main/setup.py#L26 ### Exception/Log ### Technical details: * twilio-python version: 9.0.2 * python version: 3.7
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]