SB20261007211 - Multiple vulnerabilities in aiohttp
Published: October 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 8 vulnerabilities.
1) Reliance on Untrusted Inputs in a Security Decision (CVE-ID: N/A)
CWE-ID: CWE-807 - Reliance on Untrusted Inputs in a Security Decision
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass application security logic.
The vulnerability exists due to reliance on untrusted inputs in a security decision in aiohttp's Request.scheme attribute when processing absolute-form request targets. A remote attacker can send an absolute-form request with a spoofed scheme that makes the application misidentify whether a connection is encrypted to bypass application security logic.
Exploitation requires application code that depends on the Request.scheme attribute for security decisions.
2) Missing Encryption of Sensitive Data (CVE-ID: N/A)
CWE-ID: CWE-311 - Missing Encryption of Sensitive Data
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive cookie data.
The vulnerability exists due to missing enforcement of the Secure attribute in aiohttp shared-cookie handling when sending unencrypted requests. A remote attacker can send a shared cookie marked Secure in an unencrypted request to disclose sensitive cookie data.
3) Missing Release of Resource after Effective Lifetime (CVE-ID: N/A)
CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to keep idle connections open indefinitely.
The vulnerability exists due to a missing initial request/header timeout in the aiohttp server when waiting for initial request data. A remote attacker can open a connection without sending any data to keep idle connections open indefinitely.
4) Integer overflow (CVE-ID: N/A)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to temporarily exhaust the connection pool.
The vulnerability exists due to an overflow in Max-Age processing when handling Max-Age values. A remote attacker can trigger an overflow that prevents a connection from closing to temporarily exhaust the connection pool.
Garbage collection eventually resolves the unclosed connections.
5) Origin validation error (CVE-ID: N/A)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to remove host-only protections from an existing parent-domain cookie.
The vulnerability exists due to improper enforcement of cookie origin restrictions in aiohttp cookie handling when processing cookies from a subdomain. A remote attacker can supply a cookie from an untrusted subdomain to remove host-only protections from an existing parent-domain cookie.
Exploitation requires a user to access the untrusted subdomain. Most use cases do not reflect these cookies to a browser, limiting the practical impact.
6) Inconsistent interpretation of HTTP requests (CVE-ID: N/A)
CWE-ID: CWE-444 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to smuggle HTTP requests.
The vulnerability exists due to improper HTTP request parsing in the aiohttp pure-Python parser when processing HTTP requests. A remote attacker can send crafted HTTP requests to smuggle HTTP requests.
Exposure requires use of the Python parser, including configurations using AIOHTTP_NO_EXTENSIONS or installations without a standard wheel.
7) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to exhaust file descriptors and cause resource exhaustion.
The vulnerability exists due to allocation of file descriptors without limits in Request.post() when processing multipart requests. A remote attacker can send specially crafted multipart requests to exhaust file descriptors and cause resource exhaustion.
8) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service through resource exhaustion.
The vulnerability exists due to allocation of resources without limits or throttling in aiohttp when processing attacker-controlled requests. A remote attacker can send specially crafted requests to cause a denial of service through excessive or unbounded memory use or excessive CPU consumption.
Remediation
Install update from vendor's website.
References
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-f9xw-jh8m-3mwq
- https://github.com/aio-libs/aiohttp/commit/6d4e7b01f9b951aa084a75d7356e907d4ee80411
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-494j-54xm-rwp3
- https://github.com/aio-libs/aiohttp/commit/999c356d61e966faffa97b06ab0d0455226d36c5
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-5wr8-gcqf-gqf3
- https://github.com/aio-libs/aiohttp/commit/be846822b4b3a5a54b6163e794b42dc06fba54a3
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-6cjc-53gc-5rqm
- https://github.com/aio-libs/aiohttp/commit/9dd8eaf4e31f1237ef2c1574a8c82a739fca5805
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-gx76-c99x-2c96
- https://github.com/aio-libs/aiohttp/commit/6a07c171ef9f3be583e2907dcd1931372efca8d6
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-pqxq-w44r-73xw
- https://github.com/aio-libs/aiohttp/commit/9b27347e61454d9f8ca2055f4c67a37dee336e83
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-9xw5-w5jj-pvcg
- https://github.com/aio-libs/aiohttp/commit/2d94633b7f1b4c1ba07d647b629a8440652b2d09
- https://github.com/aio-libs/aiohttp/security/advisories/GHSA-2g87-pp6c-29x5