Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-54279

Опубликовано: 22 июн. 2026
Источник: redhat
CVSS3: 4.3

Описание

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vulnerability is fixed in 3.14.1.

A flaw was found in aiohttp (before 3.14.1). Host-only cookies saved with CookieJar.save() and later restored with CookieJar.load() lose their host-only flag, so cookies intended for a single host may be sent to subdomains after persistence.

Отчет

aiohttp is vulnerable to improper cookie scope handling when persisting and reloading CookieJar data. After save/load, host-only cookies are treated as domain cookies, so session data meant for one host may be sent to subdomains on subsequent requests. Red Hat exposure is in Python asyncio services that bundle aiohttp and persist cookie jars to disk, including AI inference, AAP, and other hybrid platform Python containers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Not affected
Migration Toolkit for Applications 8mta/mta-solution-server-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Not affected
Red Hat AI Inference Serverrhaii/model-opt-cuda-rhel9Not affected
Red Hat AI Inference Serverrhaiis/model-opt-cuda-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-cuda-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-neuron-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-565
https://bugzilla.redhat.com/show_bug.cgi?id=2491450aiohttp: AIOHTTP: Host-Only Cookies Become Domain Cookies After CookieJar Persistence

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vulnerability is fixed in 3.14.1.

CVSS3: 7.5
nvd
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that are saved with CookieJar.save() and then restored later with CookieJar.load() lose their host-only status. This vulnerability is fixed in 3.14.1.

CVSS3: 7.5
debian
около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

github
около 2 месяцев назад

aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence

4.3 Medium

CVSS3