PT-2026-49564 · Pypi · Aiohttp

·

CVE-2026-50269

·

Published

2026-06-15

·

Updated

2026-07-23

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions AIOHTTP versions prior to 3.14.0
Description Attacker-controlled input included in multipart/payload headers can be used to modify a request to inject additional headers or change the request contents. This occurs when an application passes user-controlled strings into the MultipartWriter.append(headers=...) function or the Payload.headers variable.
Recommendations Update to version 3.14.0. Sanitize user input passed into multipart/payload headers.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50269
ECHO-B9F2-2C14-64AB
GHSA-M6QW-4CW2-HM4M
OPENSUSE-SU-2026:11097-1
OPENSUSE-SU-2026:21372-1
PYSEC-2026-2106
SUSE-SU-2026:22819-1
SUSE-SU-2026:3207-1
SUSE-SU-2026:3208-1

Affected Products

Aiohttp