VDB
CVE-2026-47265
CVE-2026-47265
PUBLISHED
CVSS 6.6 MEDIUM
Reported by GitHub_M · Published June 2, 2026
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter on requests are sent after following a cross-origin redirect. If a developer uses the `cookies` parameter on a per-request basis then sensitive data might be leaked to an attacker if they manage to control a redirect. Version 3.14.0 patches the issue. If unable to upgrade, using a `Cookie` header in the `headers` parameter is not vulnerable.
Risk Scores
CVSS 4.0
6.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| aio-libs | aiohttp | < 3.14.0 |
| chainguard | gitlab-cng-18.10 | 0, 0, 0 |
| chainguard | datahub-ingestion-fips | 0, 0, 0 |
| alpine | py3-aiohttp | 0, 0, 0 |
| chainguard | airflow-3 | 0, 0, 0 |
| chainguard | py3-vllm-cuda-12.4 | 0, 0, 0 |
| chainguard | dask-kubernetes-fips | 0, 0, 0 |
| chainguard | gitlab-cng-fips-18.11 | 0, 0, 0 |
| chainguard | py3-vllm-cuda-13.0 | 0, 0, 0 |
| chainguard | checkov | 0, 0, 0 |
| wolfi | airflow-3 | 0, 0, 0 |
| aio-libs | aiohttp | < 3.14.0, < 3.14.0, < 3.14.0 |
| wolfi | kubeflow-katib | 0, 0, 0 |
| chainguard | gitlab-cng-18.11 | 0, 0, 0 |
| chainguard | dask-kubernetes | 0, 0, 0 |
| chainguard | gitlab-cng-fips-18.10 | 0, 0, 0 |
| chainguard | request-1276 | 0, 0, 0 |
| chainguard | awx | 0, 0, 0 |
| chainguard | tritonserver-backend-vllm-cuda-12.9 | 0, 0, 0 |
| chainguard | airflow-core-2 | 0, 0, 0 |
…and 20 more
Timeline
- Jun 2, 2026 CVE Published
- Jun 3, 2026 CVE Updated
- Jun 4, 2026 Coalition ESS Score
- Jun 5, 2026 EPSS Score
- Jun 5, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
References
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-hg6j-4rv6-33pg x_refsource_CONFIRM
- https://github.com/aio-libs/aiohttp/commit/f54c40851b0d6c4bbdab97ba518a223adda32478 x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2026-47265 advisory
- https://github.com/advisories/GHSA-hg6j-4rv6-33pg advisory