Skip to content

chore(deps): update dependency aiohttp to v3.14.3 - #116

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/aiohttp-3.x
Open

chore(deps): update dependency aiohttp to v3.14.3#116
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/aiohttp-3.x

Conversation

@renovate

@renovate renovate Bot commented Jul 21, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
aiohttp ==3.14.1==3.14.3 age confidence

Release Notes

aio-libs/aiohttp (aiohttp)

v3.14.3: 3.14.3

Compare Source

Bug fixes

  • Fixed the client dropping only the first Authorization, Cookie and
    Proxy-Authorization header when a redirect crossed an origin -- by :user:arshsmith1.

    Related issues and pull requests on GitHub:
    #​13180.

  • Fixed error message construction in the C HTTP parser -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    #​13222.


v3.14.2: 3.14.2

Compare Source

Bug fixes

  • Fixed :py:attr:~aiohttp.web.StreamResponse.last_modified rounding a
    :class:datetime.datetime with a fractional second down.

    Related issues and pull requests on GitHub:
    #​5303.

  • Fixed resolving localhost on Windows to fall back without AI_ADDRCONFIG
    when the first lookup fails, so localhost still works without an active
    network.

    Related issues and pull requests on GitHub:
    #​5357.

  • Rejected multipart body parts whose Content-Length header is not a
    plain sequence of digits (e.g. +5, -1, 1_0), matching the
    strictness of the main request parser per :rfc:9110#section-8.6
    -- by :user:dxbjavid.

    Related issues and pull requests on GitHub:
    #​12794.

  • Fixed GunicornWebWorker endlessly reloading when app fails during startup -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    #​12879.

  • Fixed some inconsistent case sensitivity on request methods -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    #​12931.

  • Fixed IndexError: string index out of range in parse_content_disposition
    when a header parameter has an empty value (e.g. filename=).
    -- by :user:JSap0914.

    Related issues and pull requests on GitHub:
    #​12948.

  • Fixed the sock_read timeout being re-armed on a keep-alive connection after
    it had been returned to the pool. An idle pooled connection could be left with a
    pending read timeout that fired and poisoned it, so the next request reusing the
    connection failed immediately with :exc:aiohttp.SocketTimeoutError. The read
    timeout is now only rescheduled when resuming a transport that was actually
    paused -- by :user:daragok.

    Related issues and pull requests on GitHub:
    #​12953, #​12954.

  • Fixed the client decompressing frames when permessage-deflate was not negotiated -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    #​12976.

  • Fixed DigestAuthMiddleware raising an IndexError on empty domain -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    #​12983.

  • Fixed :class:~aiohttp.DigestAuthMiddleware corrupting the Digest
    challenge when a WWW-Authenticate response offered more than one
    authentication scheme -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    #​12984.

  • Fixed client not closing cleanly after an exception -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    #​12985.

  • Fixed control frames breaking fragmented WebSocket messages -- by :user:arshsmith1.

    Related issues and pull requests on GitHub:
    #​12988.

  • Fixed parse_content_disposition rejecting otherwise-valid
    Content-Disposition header values that contain optional whitespace (OWS)
    around the disposition type (e.g. "form-data ; name=\"field\"").
    The disposition type is now stripped before token validation, consistent with
    how parameter keys are already handled -- by :user:JSap0914.

    Related issues and pull requests on GitHub:
    #​12996.

  • Fixed an :exc:IndexError in the pure-Python HTTP parser -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    #​13001.

  • Fixed parsing optional whitespace in Content-Disposition -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    #​13002.

  • Fixed request body not being read on rejected WebSocket upgrades -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    #​13016.

  • Fixed :exc:LookupError (and an unguarded :exc:UnicodeDecodeError) escaping
    Content-Disposition parsing when a multipart part supplies an extended
    parameter with an unknown charset
    -- by :user:arshsmith1.

    Related issues and pull requests on GitHub:
    #​13042.

  • Fixed escape_quotes in the Digest authentication middleware not escaping
    backslashes, so a WWW-Authenticate challenge value containing a backslash
    could break out of its quoted-string in the generated Authorization header
    -- by :user:dxbjavid.

    Related issues and pull requests on GitHub:
    #​13054.

  • Fixed Python parser not rejecting a bare LF in the request line -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    #​13136.

  • Fixed the C HTTP parser folding the fragment into the query string for an
    origin-form request target with an empty query (e.g. /path?#frag),
    which diverged from the pure-Python parser -- by :user:GiulioDER.

    Related issues and pull requests on GitHub:
    #​13171.

  • Fixed the C parser reporting newer HTTP methods such as QUERY as <unknown>;
    the method table is now derived from the vendored llhttp instead of a hand-maintained count
    -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    #​13174.

Packaging updates and notes for downstreams

  • Upgraded llhttp to v9.4.2 -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    #​12956.

Contributor-facing changes

  • Added admin documentation on incident response and on running reproducer code
    safely, covering security vulnerability handling and supply-chain, account, and
    CI/infrastructure compromise -- by :user:Dreamsorcerer.

    Related issues and pull requests on GitHub:
    #​12914.



Configuration

📅 Schedule: (in timezone UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/aiohttp-3.x branch from 6c85e92 to 4b16ab3 Compare July 23, 2026 03:09
@renovate renovate Bot changed the title chore(deps): update dependency aiohttp to v3.14.2 chore(deps): update dependency aiohttp to v3.14.3 Jul 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants