Server-Side Request Forgery (SSRF) in aiohttp - CVE-2026-34515
Published: April 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to server-side request forgery in the static resource handler on Windows when handling requests for static resources that reference a UNC path. A remote attacker can supply a crafted NTLMv2 remote path to disclose sensitive information.
This issue can expose NTLMv2 hash material and may also allow reading a local file on Windows systems.
Affected software
Python for Scientific Computing
Maximo Application Suite - Predict Component
How to mitigate CVE-2026-34515
Python for Scientific Computing - update to 4.3.2
Maximo Application Suite - Predict Component - update to 9.2.1