CVE-2026-34520
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in response headers. This issue has been patched in version 3.13.4.
Scoring
- Severity
- LOW
- CVSS base score
- 9.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U
- EPSS probability
- 0.46%
- CWE
- CWE-113
- Published
- 2026-04-01
- Last modified
- 2026-04-04
Affected products
- aio-libs aiohttp
Weakness type
Related vulnerabilities
- CVE-2026-77341 — cpp-httplib: CRLF injection via unvalidated HTTP trailer headers in chunked response writing
- CVE-2026-39915 — TIM Flow < 26.0.6 CRLF Injection via rt Parameter
- CVE-2026-50576 — ePA 3.x Integration: HTTP Header Injection in VAU Inner Requests
- CVE-2026-67289 — FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection
- CVE-2026-66746 — Rouille 0.4.0 - 3.6.2 HTTP Response Splitting via Header Injection
- CVE-2026-66753 — tiny-http 0.12.0 HTTP Response Splitting via Header Injection
- CVE-2026-63771 — Adminer < 5.4.3 Cookie Injection via X-Forwarded-Prefix Header
- CVE-2026-54163 — secure_headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input