PT-2026-29604 · Aiohttp · Aiohttp
Nvn1729
·
Published
2026-04-01
·
Updated
2026-05-18
·
CVE-2026-34515
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AIOHTTP versions prior to 3.13.4
Description
Prior to version 3.13.4, on Windows, the static resource handler in AIOHTTP may expose information about a NTLMv2 remote path. This could potentially allow an attacker to extract the hash from an NTLMv2 path and then extract user credentials.
Recommendations
Update AIOHTTP to version 3.13.4 or later.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aiohttp