Skip to content

Update aiohttp to >=3.14.0 #7577

@ferrarimarco

Description

@ferrarimarco

Hi folks! Thanks for supporting the community with this tool.

Would it be possible to update aiohttp to a version >=3.14.0

There are two known vulnerabilities with the version that checkov installs:

aiohttp = ">=3.8.0,<3.14.0"

"version": "==3.13.5"

pip-audit output:

Found 2 known vulnerabilities in 1 package
Name    Version ID             Fix Versions
------- ------- -------------- ------------
aiohttp 3.13.5  CVE-2026-34993 3.14.0
aiohttp 3.13.5  CVE-2026-47265 3.14.0

Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions