SB20261007211 - Multiple vulnerabilities in aiohttp



SB20261007211 - Multiple vulnerabilities in aiohttp

Published: October 7, 2026

Security Bulletin ID SB20261007211
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 8
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 88% Low 13%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 8 vulnerabilities.


1) Reliance on Untrusted Inputs in a Security Decision (CVE-ID: N/A)

CWE-ID: CWE-807 - Reliance on Untrusted Inputs in a Security Decision

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass application security logic.

The vulnerability exists due to reliance on untrusted inputs in a security decision in aiohttp's Request.scheme attribute when processing absolute-form request targets. A remote attacker can send an absolute-form request with a spoofed scheme that makes the application misidentify whether a connection is encrypted to bypass application security logic.

Exploitation requires application code that depends on the Request.scheme attribute for security decisions.


2) Missing Encryption of Sensitive Data (CVE-ID: N/A)

CWE-ID: CWE-311 - Missing Encryption of Sensitive Data

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive cookie data.

The vulnerability exists due to missing enforcement of the Secure attribute in aiohttp shared-cookie handling when sending unencrypted requests. A remote attacker can send a shared cookie marked Secure in an unencrypted request to disclose sensitive cookie data.


3) Missing Release of Resource after Effective Lifetime (CVE-ID: N/A)

CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to keep idle connections open indefinitely.

The vulnerability exists due to a missing initial request/header timeout in the aiohttp server when waiting for initial request data. A remote attacker can open a connection without sending any data to keep idle connections open indefinitely.


4) Integer overflow (CVE-ID: N/A)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to temporarily exhaust the connection pool.

The vulnerability exists due to an overflow in Max-Age processing when handling Max-Age values. A remote attacker can trigger an overflow that prevents a connection from closing to temporarily exhaust the connection pool.

Garbage collection eventually resolves the unclosed connections.


5) Origin validation error (CVE-ID: N/A)

CWE-ID: CWE-346 - Origin Validation Error

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to remove host-only protections from an existing parent-domain cookie.

The vulnerability exists due to improper enforcement of cookie origin restrictions in aiohttp cookie handling when processing cookies from a subdomain. A remote attacker can supply a cookie from an untrusted subdomain to remove host-only protections from an existing parent-domain cookie.

Exploitation requires a user to access the untrusted subdomain. Most use cases do not reflect these cookies to a browser, limiting the practical impact.


6) Inconsistent interpretation of HTTP requests (CVE-ID: N/A)

CWE-ID: CWE-444 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to smuggle HTTP requests.

The vulnerability exists due to improper HTTP request parsing in the aiohttp pure-Python parser when processing HTTP requests. A remote attacker can send crafted HTTP requests to smuggle HTTP requests.

Exposure requires use of the Python parser, including configurations using AIOHTTP_NO_EXTENSIONS or installations without a standard wheel.


7) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to exhaust file descriptors and cause resource exhaustion.

The vulnerability exists due to allocation of file descriptors without limits in Request.post() when processing multipart requests. A remote attacker can send specially crafted multipart requests to exhaust file descriptors and cause resource exhaustion.


8) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service through resource exhaustion.

The vulnerability exists due to allocation of resources without limits or throttling in aiohttp when processing attacker-controlled requests. A remote attacker can send specially crafted requests to cause a denial of service through excessive or unbounded memory use or excessive CPU consumption.


Remediation

Install update from vendor's website.