VDB
DEBIAN-CVE-2026-34525
DEBIAN-CVE-2026-34525
PUBLISHED
CVSS 5.300000190734863 MEDIUM
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.
Risk Scores
CVSS v3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:14 | python-aiohttp | 3.11.16-1, 3.13.5-1, 3.13.3-3 |
| Debian:11 | python-aiohttp | 3.10.3-1, 0, 3.10.1-1 |
| Debian:13 | python-aiohttp | 3.13.5-1, 3.13.3-3, 3.13.3-2 |
| Debian:12 | python-aiohttp | 0, 3.10.1-1, 3.10.10-1 |
Timeline
- Apr 1, 2026 CVE Published
- Apr 28, 2026 CVE Updated