VDB
CVE-2026-50269
CVE-2026-50269
PUBLISHED
CVSS 2.7 LOW
Reported by GitHub_M · Published June 22, 2026
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/payload headers can be used to modify a request to inject additional headers or similar. In the unlikely situation that an application is passing user-controlled strings into MultipartWriter.append(headers=...) or Payload.headers, then an attacker may be able to modify the request to inject headers or change the contents of the request. This vulnerability is fixed in 3.14.0.
Risk Scores
CVSS 4.0
2.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| aio-libs | aiohttp | < 3.14.0 |
| chainguard | tritonserver-backend-vllm-cuda-12.9 | 0, 0, 0 |
| chainguard | py3-vllm-cuda-12.4 | 0, 0, 0 |
| chainguard | py3-vllm-cuda-13.0 | 0, 0, 0 |
| wolfi | airflow-3 | 0, 0, 0 |
| alpine | py3-aiohttp | 0, 0, 0 |
| aio-libs | aiohttp | < 3.14.0, < 3.14.0 |
| PyPI | aiohttp | 0 |
| chainguard | lmcache-cuda-12.8 | 0, 0, 0 |
| chainguard | airflow-3 | 0, 0 |
| chainguard | py3.13-scanner-test-libraries-aiohttp | 0, 0, 0 |
| chainguard | airflow-core-2 | 0, 0, 0 |
| chainguard | py3-vllm-cuda-12.9 | 0, 0, 0 |
Timeline
- Jun 15, 2026 CVE Published
- Jun 23, 2026 Security Advisory
- Jun 26, 2026 CVE Updated
- Jul 4, 2026 EPSS Score
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 29, 2026 EPSS Score
- Sep 4, 2026 EPSS Score
References
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-m6qw-4cw2-hm4m x_refsource_CONFIRM
- https://github.com/aio-libs/aiohttp/commit/bf88077ebb14f4c29924b8e8904cba20c55c28b8 x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2026-50269 advisory
- https://github.com/advisories/GHSA-m6qw-4cw2-hm4m advisory