PT-2026-49593 · Pypi · Aiohttp

·

CVE-2026-54279

·

Published

2026-06-15

·

Updated

2026-07-23

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions AIOHTTP versions prior to 3.14.1
Description Host-only cookies saved using the CookieJar.save() function and subsequently restored via the CookieJar.load() function lose their host-only status. This can result in cookies loaded from disk being sent to subdomains that should have been disallowed.
Recommendations Update to version 3.14.1.

Exploit

Fix

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54279
ECHO-F4DA-5CDF-F6C3
GHSA-2FQR-MR3J-6WP8
OESA-2026-2838
OESA-2026-2839
OPENSUSE-SU-2026:11097-1
OPENSUSE-SU-2026:21372-1
PYSEC-2026-2112
SUSE-SU-2026:22819-1
SUSE-SU-2026:3207-1
SUSE-SU-2026:3208-1

Affected Products

Aiohttp