Missing Encryption of Sensitive Data in aiohttp - #VU153857
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive cookie data.
The vulnerability exists due to missing enforcement of the Secure attribute in aiohttp shared-cookie handling when sending unencrypted requests. A remote attacker can send a shared cookie marked Secure in an unencrypted request to disclose sensitive cookie data.