PT-2026-45829 · Pypi · Aiohttp

·

CVE-2026-34993

·

Published

2026-06-02

·

Updated

2026-09-03

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AIOHTTP versions prior to 3.14.0
Description Using the CookieJar.load() function with untrusted input may allow arbitrary code execution. This issue is unlikely to affect many applications as most use this function with the user's own data.
Recommendations Update to version 3.14.0. As a temporary workaround for older releases, sanitize files before loading if the application allows attacker-controlled files to be loaded.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-89330
CVE-2026-34993
ECHO-1919-21B7-3A3E
GHSA-JG22-MG44-37J8
OESA-2026-2562
OESA-2026-2563
OPENSUSE-SU-2026:10963-1
OPENSUSE-SU-2026:21098-1
PYSEC-2026-2104
RHSA-2026:50319
RHSA-2026:50336
SUSE-SU-2026:22173-1
SUSE-SU-2026:3059-1
SUSE-SU-2026:3207-1

Affected Products

Aiohttp