PT-2026-29608 · Aiohttp · Aiohttp

Dhiral2908

·

Published

2026-04-01

·

Updated

2026-05-18

·

CVE-2026-34519

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions AIOHTTP versions prior to 3.13.4
Description AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. An attacker controlling the reason parameter when creating a Response may inject extra headers or similar exploits. This could allow manipulation of the response to send unintended data if untrusted data is used in the reason parameter.
Recommendations Update to version 3.13.4 or later.

Fix

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-AN27706
CVE-2026-34519
ECHO-ABE8-B546-AD42
GHSA-MWH4-6H8G-PG8W
OESA-2026-2192
OESA-2026-2193
OESA-2026-2194

Affected Products

Aiohttp