You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
## Closeselastic/security#12492
Bump `aiohttp` from 3.12.14 to 3.13.3 to address CVE-2025-69223
(zip-bomb DoS via HTTP parser `auto_decompress` on the aiohttp server).
Connectors uses aiohttp as an HTTP client only and is not affected by
the server-side attack path; the bump clears the CVE from scanners and
keeps the dependency current.
### Scanner A/B (`CVE-2025-69223`)
| Tool | Before | After |
|------|--------|-------|
| pip-audit | reported | clear |
| Trivy | reported | clear |
| Snyk | reported | clear |
## Checklists
#### Pre-Review Checklist
- [x] this PR does NOT contain credentials of any kind, such as API keys
or username/passwords (double check `config.yml.example`)
- [x] this PR has a meaningful title
- [x] this PR links to all relevant github issues that it fixes or
partially addresses
- [x] this PR has a thorough description
- [x] Covered the changes with automated tests
- [x] Tested the changes locally
- [x] Added a label for each target release version (example: `v7.13.2`,
`v7.14.0`, `v8.0.0`)
- [x] For bugfixes: backport safely to all minor branches still
receiving patch releases
#### Changes Requiring Extra Attention
- [x] Security-related changes (encryption, TLS, SSRF, etc)
## Release Note
Bump aiohttp to 3.13.3 to address CVE-2025-69223.
Made with [Cursor](https://cursor.com)
---------
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Elastic Machine <elasticmachine@users.noreply.github.com>
0 commit comments