Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-34525

Опубликовано: 01 апр. 2026
Источник: debian
EPSS Низкий

Описание

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-aiohttpfixed3.13.5-1package
python-aiohttpno-dsatrixiepackage
python-aiohttpno-dsabookwormpackage

Примечания

  • https://github.com/aio-libs/aiohttp/security/advisories/GHSA-c427-h43c-vf67

  • Fixed by: https://github.com/aio-libs/aiohttp/commit/e00ca3cca92c465c7913c4beb763a72da9ed8349 (v3.13.4)

  • Fixed by: https://github.com/aio-libs/aiohttp/commit/53e2e6fc58b89c6185be7820bd2c9f40216b3000 (v3.13.5)

EPSS

Процентиль: 21%
0.00288
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.

CVSS3: 5.4
redhat
4 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.

CVSS3: 5.3
nvd
4 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.

github
4 месяца назад

AIOHTTP accepts duplicate Host headers

CVSS3: 5.3
fstec
5 месяцев назад

Уязвимость функции Application.add_domain() HTTP-клиента aiohttp, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 21%
0.00288
Низкий