Improper access control in aiohttp - CVE-2026-47265
Published: June 2, 2026
aiohttp
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in request redirect handling when following a cross-origin redirect after setting per-request cookies. A remote attacker can control a redirect to disclose sensitive information.
The issue occurs only when cookies are supplied through the per-request cookies parameter.