- Sources: GHSA-5x7x-4c3c-qf5w, GHSA-3cgp-3cqx-j8w2, GHSA-jqhh-cjmq-vmv6, release
- Summary: CVE-2026-88001, affecting 0.9.5 through 0.11.0, lets any authenticated user reach excluded hosts and cloud metadata endpoints through unvalidated redirect targets, on deployments that set AIOHTTP_CLIENT_ALLOW_REDIRECTS to true, which is not the default. CVE-2026-88000, affecting 0.10.0 up to 0.11.1, lets any default-role user pin a worker core with a cyclic chat history at flat memory, blocking every other request including unauthenticated health checks, and the process has to be killed rather than reclaimed. CVE-2026-88002, affecting 0.5.0 up to 0.11.1, instead grows a list without bound until a memory-capped deployment takes an OOM kill, and the malformed chat survives a restart and hangs the new process on the next request that walks it until the stored chat is deleted.
- Why it matters: The 0.5.0 floor on CVE-2026-88002 reaches back across most deployed versions, and operators who route fetches through a forward proxy have to restrict destinations at the proxy as well, because the upgrade to 0.11.1 alone does not cover that path.
send feedback on this story