PT-2026-45836 · Pypi · Aiohttp

·

CVE-2026-47265

·

Published

2026-06-02

·

Updated

2026-08-21

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AIOHTTP versions prior to 3.14.0
Description Cookies set using the cookies parameter on requests are sent after following a cross-origin redirect. This behavior can lead to the leakage of sensitive data to an attacker if they can control the redirect destination.
Recommendations Update to version 3.14.0. As a temporary workaround, use a Cookie header within the headers parameter instead of the cookies parameter.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-89333
CVE-2026-47265
ECHO-9113-79E2-CA65
GHSA-HG6J-4RV6-33PG
OESA-2026-2562
OESA-2026-2563
OPENSUSE-SU-2026:21098-1
PYSEC-2026-2105
SUSE-SU-2026:22173-1
SUSE-SU-2026:3059-1
SUSE-SU-2026:3207-1

Affected Products

Aiohttp