Origin validation error in aiohttp - #VU153860
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to remove host-only protections from an existing parent-domain cookie.
The vulnerability exists due to improper enforcement of cookie origin restrictions in aiohttp cookie handling when processing cookies from a subdomain. A remote attacker can supply a cookie from an untrusted subdomain to remove host-only protections from an existing parent-domain cookie.
Exploitation requires a user to access the untrusted subdomain. Most use cases do not reflect these cookies to a browser, limiting the practical impact.