PT-2026-29607 · Aiohttp · Aiohttp
Uug4Na
·
Published
2026-04-01
·
Updated
2026-05-18
·
CVE-2026-34518
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AIOHTTP versions prior to 3.13.4
Description
When following redirects to a different origin, aiohttp removes the
Authorization header while keeping the Cookie and Proxy-Authorization headers. This could lead to the leakage of sensitive information contained in the Cookie and Proxy-Authorization headers to an unintended party.Recommendations
Update to AIOHTTP version 3.13.4 or later.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Aiohttp