Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2fqr-mr3j-6wp8

Опубликовано: 15 июн. 2026
Источник: github
Github: Прошло ревью
CVSS4: 1.3

Описание

aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence

Summary

Host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status.

Impact

Host-only cookies that have been loaded from disk may get sent to subdomains that previously should have been disallowed.


Patch: https://github.com/aio-libs/aiohttp/commit/a329a7aacad5284f087af36103aff778746da0f2

Пакеты

Наименование

aiohttp

pip
Затронутые версииВерсия исправления

<= 3.14.0

3.14.1

EPSS

Процентиль: 20%
0.00279
Низкий

1.3 Low

CVSS4

Дефекты

CWE-665

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vulnerability is fixed in 3.14.1.

CVSS3: 4.3
redhat
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vulnerability is fixed in 3.14.1.

CVSS3: 7.5
nvd
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vulnerability is fixed in 3.14.1.

CVSS3: 7.5
debian
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

suse-cvrf
18 дней назад

Security update for python-aiohttp

EPSS

Процентиль: 20%
0.00279
Низкий

1.3 Low

CVSS4

Дефекты

CWE-665