CVE-2026-34993

medium

Description

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications. Version 3.14.0 patches the issue. If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitize the files before loading.

References

https://github.com/aio-libs/aiohttp/security/advisories/GHSA-jg22-mg44-37j8

https://github.com/aio-libs/aiohttp/commit/dcf40f30637e8752c76781cf6703b5a236749a00

Details

Source: Mitre, NVD

Published: 2026-06-02

Updated: 2026-06-02

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:L/AC:H/Au:M/C:P/I:C/A:P

Severity: Medium

CVSS v3

Base Score: 6.4

Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:L

Severity: Medium

EPSS

EPSS: 0.00055