AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.
References
Configurations
History
16 Apr 2026, 16:21
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:aiohttp:aiohttp:*:*:*:*:*:*:*:* | |
| First Time |
Aiohttp aiohttp
Aiohttp |
|
| References | () https://github.com/aio-libs/aiohttp/commit/53e2e6fc58b89c6185be7820bd2c9f40216b3000 - Patch | |
| References | () https://github.com/aio-libs/aiohttp/commit/e00ca3cca92c465c7913c4beb763a72da9ed8349 - Patch | |
| References | () https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4 - Release Notes | |
| References | () https://github.com/aio-libs/aiohttp/security/advisories/GHSA-c427-h43c-vf67 - Patch, Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
01 Apr 2026, 21:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-01 21:17
Updated : 2026-04-16 16:21
NVD link : CVE-2026-34525
Mitre link : CVE-2026-34525
CVE.ORG link : CVE-2026-34525
JSON object : View
Products Affected
aiohttp
- aiohttp
