VDB
CVE-2026-54279
CVE-2026-54279
PUBLISHED
CVSS 1.3 LOW
Reported by GitHub_M · Published June 22, 2026
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vulnerability is fixed in 3.14.1.
Risk Scores
CVSS 4.0
1.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:U
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| aio-libs | aiohttp | < 3.14.1 |
| chainguard | text-generation-inference | 0, 0, 0 |
| chainguard | airflow-3 | 0, 0, 0 |
| wolfi | airflow-3 | 0, 0, 0 |
| wolfi | mlflow | 0, 0, 0 |
| PyPI | aiohttp | 0 |
| chainguard | dask-kubernetes-fips | 0, 0, 0 |
| chainguard | py3-vllm-cuda-13.0 | 0, 0, 0 |
| chainguard | apache-beam-python-3.12-sdk | 0, 0, 0 |
| chainguard | airflow-core-2 | 0, 0, 0 |
| chainguard | mlflow | 0, 0, 0 |
| chainguard | open-webui | 0, 0, 0 |
| chainguard | mlflow-fips | 0, 0, 0 |
| chainguard | metaflow-service-fips | 0, 0, 0 |
| chainguard | request-1276 | 0, 0, 0 |
| chainguard | authentik-2026.2 | 0, 0, 0 |
| chainguard | awx | 0, 0, 0 |
| wolfi | open-webui | 0, 0, 0 |
| chainguard | tritonserver-backend-vllm-cuda-13.0 | 0, 0, 0 |
| chainguard | py3.13-scanner-test-libraries-aiohttp | 0, 0, 0 |
…and 10 more
Timeline
- Jun 15, 2026 CVE Published
- Jun 23, 2026 Security Advisory
- Jul 4, 2026 EPSS Score
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Sep 4, 2026 EPSS Score
References
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-2fqr-mr3j-6wp8 x_refsource_CONFIRM
- https://github.com/aio-libs/aiohttp/commit/a329a7aacad5284f087af36103aff778746da0f2 x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2026-54279 advisory
- https://github.com/advisories/GHSA-2fqr-mr3j-6wp8 advisory