PT-2026-29607 · Aiohttp+1 · Aiohttp+1

·

CVE-2026-34518

·

Published

2026-02-27

·

Updated

2026-07-15

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AIOHTTP versions prior to 3.13.4
Description When following redirects to a different origin, aiohttp removes the Authorization header while keeping the Cookie and Proxy-Authorization headers. This could lead to the leakage of sensitive information contained in the Cookie and Proxy-Authorization headers to an unintended party.
Recommendations Update to AIOHTTP version 3.13.4 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09576
CLEANSTART-2026-AN27706
CLEANSTART-2026-AZ09261
CLEANSTART-2026-CQ05396
CLEANSTART-2026-FU07345
CLEANSTART-2026-KE11953
CLEANSTART-2026-MR94452
CLEANSTART-2026-NM83456
CLEANSTART-2026-QE89118
CLEANSTART-2026-SO50412
CLEANSTART-2026-WQ85001
CLEANSTART-2026-WU03167
CVE-2026-34518
ECHO-758D-EDBE-6881
GHSA-966J-VMVW-G2G9
OESA-2026-2192
OESA-2026-2193
OESA-2026-2194
OPENSUSE-SU-2026:21098-1
PYSEC-2026-2100
SUSE-SU-2026:22173-1
SUSE-SU-2026:3059-1

Affected Products

Aiohttp
Red Os