PT-2026-49590 · Pypi · Aiohttp

·

CVE-2026-54276

·

Published

2026-06-15

·

Updated

2026-07-20

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions AIOHTTP versions prior to 3.14.1
Description DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. If a client follows a redirect to an attacker-controlled domain, the attacker may be able to extract the authentication digest. This scenario likely requires an open redirect or a similar issue on the target domain. The attacker would only receive the digest, meaning credentials could only be extracted if the cryptography is weak or if password reuse occurs.
Recommendations Update to version 3.14.1. As a temporary workaround, disable follow redirects.

Exploit

Fix

Insufficiently Protected Credentials

Open Redirect

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54276
ECHO-063C-9C61-C3D6
GHSA-HPJ7-WQ8M-9HGP
OESA-2026-2838
OESA-2026-2839
PYSEC-2026-2109

Affected Products

Aiohttp