Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c427-h43c-vf67

Опубликовано: 01 апр. 2026
Источник: github
Github: Прошло ревью
CVSS4: 6.3

Описание

AIOHTTP accepts duplicate Host headers

Summary

Multiple Host headers were allowed in aiohttp.

Impact

Mostly this doesn't affect aiohttp security itself, but if a reverse proxy is applying security rules depending on the target Host, it is theoretically possible that the proxy and aiohttp could process different host names, possibly resulting in bypassing a security check on the proxy and getting a request processed by aiohttp in a privileged sub app when using Application.add_domain().


Patch: https://github.com/aio-libs/aiohttp/commit/e00ca3cca92c465c7913c4beb763a72da9ed8349 Patch: https://github.com/aio-libs/aiohttp/commit/53e2e6fc58b89c6185be7820bd2c9f40216b3000

Пакеты

Наименование

aiohttp

pip
Затронутые версииВерсия исправления

<= 3.13.3

3.13.4

EPSS

Процентиль: 21%
0.00288
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-20
CWE-444

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.

CVSS3: 5.4
redhat
4 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.

CVSS3: 5.3
nvd
4 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, multiple Host headers were allowed in aiohttp. This issue has been patched in version 3.13.4.

CVSS3: 5.3
debian
4 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

CVSS3: 5.3
fstec
5 месяцев назад

Уязвимость функции Application.add_domain() HTTP-клиента aiohttp, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 21%
0.00288
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-20
CWE-444