VDB
GHSA-966j-vmvw-g2g9
GHSA-966j-vmvw-g2g9
PUBLISHED
CVSS 5.300000190734863 MEDIUM
AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| PyPI | aiohttp | 0, 3.13.4, 0 |
Exploit Intelligence
- tmp_audit.json (github-poc)
- tmp_audit.json (github-poc)
- 8.4-dev.yaml (github-poc)
- 8.4-dev.yaml (github-poc)
Timeline
- Apr 1, 2026 CVE Published
- Apr 9, 2026 Security Advisory
- Apr 24, 2026 CVE Updated
References
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-966j-vmvw-g2g9 url
- https://nvd.nist.gov/vuln/detail/CVE-2026-34518 advisory
- https://github.com/aio-libs/aiohttp/commit/5351c980dcec7ad385730efdf4e1f4338b24fdb6 url
- https://github.com/aio-libs/aiohttp package
- https://github.com/aio-libs/aiohttp/releases/tag/v3.13.4 url
- AIOHTTP leaks Cookie and Proxy-Authorization headers on cross-origin redirect advisory