PT-2026-49590 · Pypi · Aiohttp
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
AIOHTTP versions prior to 3.14.1
Description
DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. If a client follows a redirect to an attacker-controlled domain, the attacker may be able to extract the authentication digest. This scenario likely requires an open redirect or a similar issue on the target domain. The attacker would only receive the digest, meaning credentials could only be extracted if the cryptography is weak or if password reuse occurs.Recommendations
Update to version 3.14.1.
As a temporary workaround, disable
follow redirects.Exploit
Fix
Insufficiently Protected Credentials
Open Redirect
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Aiohttp