AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most appli…
Medium CVSS 6.4
Summary
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications. Version 3.14.0 patches the issue. If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitize the files before loading.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/aio-libs/aiohttp/commit/dcf40f30637e8752c76781cf6703b5a236749a00 Patch
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-jg22-mg44-37j8 Mitigation
- https://access.redhat.com/errata/RHSA-2026:24977
- https://access.redhat.com/errata/RHSA-2026:34456
- https://access.redhat.com/errata/RHSA-2026:37275
- https://access.redhat.com/errata/RHSA-2026:42644
- https://access.redhat.com/errata/RHSA-2026:43038
- https://access.redhat.com/errata/RHSA-2026:50319
- https://access.redhat.com/errata/RHSA-2026:50336
- https://access.redhat.com/errata/RHSA-2026:50340
- https://access.redhat.com/errata/RHSA-2026:50357
- https://access.redhat.com/errata/RHSA-2026:50479
- https://access.redhat.com/security/cve/CVE-2026-34993
- https://bugzilla.redhat.com/show_bug.cgi?id=2484099
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34993.json
Timeline
- nvd_ingest NVD