Reliance on Untrusted Inputs in a Security Decision in aiohttp - #VU153856
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass application security logic.
The vulnerability exists due to reliance on untrusted inputs in a security decision in aiohttp's Request.scheme attribute when processing absolute-form request targets. A remote attacker can send an absolute-form request with a spoofed scheme that makes the application misidentify whether a connection is encrypted to bypass application security logic.
Exploitation requires application code that depends on the Request.scheme attribute for security decisions.