Improper Certificate Validation in aiohttp - #VU133990
Published: June 9, 2026
aiohttp
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass TLS hostname verification.
The vulnerability exists due to improper certificate validation in HTTPS connection reuse when reusing an existing connection for later requests with different per-request server_hostname parameters. A remote attacker can cause connection reuse to bypass TLS hostname verification.