Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 8

Количество 8

github логотип

GHSA-4m7w-qmgq-4wj5

около 2 месяцев назад

aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections

EPSS: Низкий
ubuntu логотип

CVE-2026-54275

около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS SNI check can be bypassed when an existing connection is reused. If an application makes multiple requests to the same domain, but with different per-request server_hostname parameters, then the later calls may succeed by reusing the existing connection when they should have been rejected due to the TLS SNI check. This vulnerability is fixed in 3.14.1.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-54275

около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS SNI check can be bypassed when an existing connection is reused. If an application makes multiple requests to the same domain, but with different per-request server_hostname parameters, then the later calls may succeed by reusing the existing connection when they should have been rejected due to the TLS SNI check. This vulnerability is fixed in 3.14.1.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2026-54275

около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS SNI check can be bypassed when an existing connection is reused. If an application makes multiple requests to the same domain, but with different per-request server_hostname parameters, then the later calls may succeed by reusing the existing connection when they should have been rejected due to the TLS SNI check. This vulnerability is fixed in 3.14.1.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-54275

около 1 месяца назад

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21372-1

18 дней назад

Security update for python-aiohttp

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3208-1

12 дней назад

Security update for python-aiohttp

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3207-1

12 дней назад

Security update for python-aiohttp

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4m7w-qmgq-4wj5

aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections

0%
Низкий
около 2 месяцев назад
ubuntu логотип
CVE-2026-54275

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS SNI check can be bypassed when an existing connection is reused. If an application makes multiple requests to the same domain, but with different per-request server_hostname parameters, then the later calls may succeed by reusing the existing connection when they should have been rejected due to the TLS SNI check. This vulnerability is fixed in 3.14.1.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-54275

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS SNI check can be bypassed when an existing connection is reused. If an application makes multiple requests to the same domain, but with different per-request server_hostname parameters, then the later calls may succeed by reusing the existing connection when they should have been rejected due to the TLS SNI check. This vulnerability is fixed in 3.14.1.

CVSS3: 4.8
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-54275

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS SNI check can be bypassed when an existing connection is reused. If an application makes multiple requests to the same domain, but with different per-request server_hostname parameters, then the later calls may succeed by reusing the existing connection when they should have been rejected due to the TLS SNI check. This vulnerability is fixed in 3.14.1.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-54275

AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21372-1

Security update for python-aiohttp

18 дней назад
suse-cvrf логотип
SUSE-SU-2026:3208-1

Security update for python-aiohttp

12 дней назад
suse-cvrf логотип
SUSE-SU-2026:3207-1

Security update for python-aiohttp

12 дней назад

Уязвимостей на страницу