VDB

CVE-2026-50269

CVE-2026-50269 PUBLISHED CVSS 2.7 LOW

Reported by GitHub_M · Published June 22, 2026

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled input included into multipart/payload headers can be used to modify a request to inject additional headers or similar. In the unlikely situation that an application is passing user-controlled strings into MultipartWriter.append(headers=...) or Payload.headers, then an attacker may be able to modify the request to inject headers or change the contents of the request. This vulnerability is fixed in 3.14.0.

Risk Scores

CVSS 4.0
2.7
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U

Affected Products

VendorProductVersions
aio-libsaiohttp< 3.14.0
chainguardtritonserver-backend-vllm-cuda-12.90, 0, 0
chainguardpy3-vllm-cuda-12.40, 0, 0
chainguardpy3-vllm-cuda-13.00, 0, 0
wolfiairflow-30, 0, 0
alpinepy3-aiohttp0, 0, 0
aio-libsaiohttp< 3.14.0, < 3.14.0
PyPIaiohttp0
chainguardlmcache-cuda-12.80, 0, 0
chainguardairflow-30, 0
chainguardpy3.13-scanner-test-libraries-aiohttp0, 0, 0
chainguardairflow-core-20, 0, 0
chainguardpy3-vllm-cuda-12.90, 0, 0

Timeline

  • Jun 15, 2026 CVE Published
  • Jun 23, 2026 Security Advisory
  • Jun 26, 2026 CVE Updated
  • Jul 4, 2026 EPSS Score
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score
  • Aug 29, 2026 EPSS Score
  • Sep 4, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›