Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2vrm-gr82-f7m5

Опубликовано: 01 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 2.7

Описание

AIOHTTP has CRLF injection through multipart part content type header construction

Summary

An attacker who controls the content_type parameter in aiohttp could use this to inject extra headers or similar exploits.

Impact

If an application allows untrusted data to be used for the multipart content_type parameter when constructing a request, an attacker may be able to manipulate the request to send something other than what the developer intended.


Patch: https://github.com/aio-libs/aiohttp/commit/9a6ada97e2c6cf1ce31727c6c9fcea17c21f6f06

Пакеты

Наименование

aiohttp

pip
Затронутые версииВерсия исправления

<= 3.13.3

3.13.4

EPSS

Процентиль: 24%
0.00315
Низкий

2.7 Low

CVSS4

Дефекты

CWE-113

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the content_type parameter in aiohttp could use this to inject extra headers or similar exploits. This issue has been patched in version 3.13.4.

CVSS3: 5.3
redhat
4 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the content_type parameter in aiohttp could use this to inject extra headers or similar exploits. This issue has been patched in version 3.13.4.

CVSS3: 5.3
nvd
4 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, an attacker who controls the content_type parameter in aiohttp could use this to inject extra headers or similar exploits. This issue has been patched in version 3.13.4.

CVSS3: 5.3
debian
4 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

CVSS3: 5.3
fstec
5 месяцев назад

Уязвимость HTTP-клиента aiohttp, связанная с непринятием мер по обработке последовательностей CRLF в HTTP-заголовках, позволяющая нарушителю внедрить произвольные HTTP-заголовки

EPSS

Процентиль: 24%
0.00315
Низкий

2.7 Low

CVSS4

Дефекты

CWE-113