VDB
CVE-2026-34993
CVE-2026-34993
PUBLISHED
CVSS 6.4 MEDIUM
Reported by GitHub_M · Published June 2, 2026
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. Most applications using this function will be doing so with the user's own data, so this is unlikely to affect many applications. Version 3.14.0 patches the issue. If an application does allow attacker controlled files to be loaded, a workaround on older releases would be to sanitize the files before loading.
Risk Scores
CVSS 3.1
6.4
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| aio-libs | aiohttp | < 3.14.0 |
| Red Hat | Red Hat OpenShift AI 3.4 | 1782132163, 1782132163, 1782132163 |
| Red Hat | Red Hat Ansible Automation Platform 2 | |
| Red Hat | Red Hat Ansible Automation Platform 2.6 for RHEL 9 | 0:3.14.1-2.el9ap, 0:3.14.1-2.el9ap, 0:3.14.1-2.el9ap |
| Red Hat | Red Hat Ansible Automation Platform 2 | |
| Red Hat | Red Hat OpenShift AI (RHOAI) | |
| Red Hat | Red Hat Ansible Automation Platform 2 | |
| Red Hat | Red Hat Discovery 2 | 1786638573, 1786638573, 1786638573 |
| Red Hat | Red Hat AI Inference Server | |
| Red Hat | Red Hat OpenShift AI 3.4 | 1782132236, 1782132236, 1782132236 |
| Red Hat | Red Hat Ansible Automation Platform 2.5 for RHEL 9 | 0:3.14.1-2.el9ap, 0:3.14.1-2.el9ap, 0:3.14.1-2.el9ap |
| Red Hat | Red Hat OpenShift AI (RHOAI) | |
| chainguard | dask-kubernetes-fips | 0, 0, 0 |
| Red Hat | Red Hat Ansible Automation Platform Ansible Core 2 | |
| Red Hat | Red Hat AI Inference Server | |
| chainguard | py3-vllm-cuda-13.0 | 0, 0, 0 |
| Red Hat | Red Hat OpenShift AI (RHOAI) | |
| Red Hat | Red Hat Enterprise Linux AI (RHEL AI) 3 | |
| Red Hat | Red Hat Ansible Automation Platform 2.6 for RHEL 9 | 0:4.7.16-1.el9ap |
| chainguard | gitlab-cng-fips-18.10 | 0, 0, 0 |
…and 176 more
Timeline
- Jun 2, 2026 CVE Published
- Jun 5, 2026 EPSS Score
- Jun 5, 2026 Security Advisory
- Jun 10, 2026 Coalition ESS Score
- Aug 7, 2026 EPSS Score
- Aug 7, 2026 Distribution Patch
- Aug 7, 2026 Security Advisory
- Aug 7, 2026 Distribution Patch
- Aug 7, 2026 Security Advisory
- Aug 7, 2026 Distribution Patch
- Aug 7, 2026 Distribution Patch
- Aug 7, 2026 Distribution Patch
References
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-jg22-mg44-37j8 x_refsource_CONFIRM
- https://github.com/aio-libs/aiohttp/commit/dcf40f30637e8752c76781cf6703b5a236749a00 x_refsource_MISC
- https://access.redhat.com/security/cve/CVE-2026-34993 vdb
- RHBZ#2484099 issue
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34993.json url
- https://access.redhat.com/errata/RHSA-2026:59135 vendor-advisory
- https://access.redhat.com/errata/RHSA-2026:50319 vendor-advisory
- https://access.redhat.com/errata/RHSA-2026:59136 vendor-advisory
- https://access.redhat.com/errata/RHSA-2026:50336 vendor-advisory
- https://access.redhat.com/errata/RHSA-2026:50357 vendor-advisory
- https://access.redhat.com/errata/RHSA-2026:50479 vendor-advisory
- https://access.redhat.com/errata/RHSA-2026:50340 vendor-advisory
- https://access.redhat.com/errata/RHSA-2026:54760 vendor-advisory
- https://access.redhat.com/errata/RHSA-2026:43038 vendor-advisory
- https://access.redhat.com/errata/RHSA-2026:42644 vendor-advisory
- https://access.redhat.com/errata/RHSA-2026:24977 vendor-advisory
- https://access.redhat.com/errata/RHSA-2026:37275 vendor-advisory
- https://access.redhat.com/errata/RHSA-2026:34456 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-34993 advisory
- https://github.com/advisories/GHSA-jg22-mg44-37j8 advisory