Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-54279

Опубликовано: 22 июн. 2026
Источник: debian
EPSS Низкий

Описание

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vulnerability is fixed in 3.14.1.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-aiohttpfixed3.14.1-1package
python-aiohttpno-dsatrixiepackage

Примечания

  • https://github.com/aio-libs/aiohttp/security/advisories/GHSA-2fqr-mr3j-6wp8

  • Fixed by: https://github.com/aio-libs/aiohttp/commit/a329a7aacad5284f087af36103aff778746da0f2 (v3.14.1)

EPSS

Процентиль: 20%
0.00279
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vulnerability is fixed in 3.14.1.

CVSS3: 4.3
redhat
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vulnerability is fixed in 3.14.1.

CVSS3: 7.5
nvd
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vulnerability is fixed in 3.14.1.

github
около 2 месяцев назад

aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence

suse-cvrf
18 дней назад

Security update for python-aiohttp

EPSS

Процентиль: 20%
0.00279
Низкий